Detections
Explore public detection logic contributed by the community across SIEM and rule languages.
48 detections
Filters
Last updated
All Time
Detection languages
12
11
7
5
5
Contributors
23
20
1
1
1
Categories
13
11
11
8
7
Platforms
45
3
Products / Services
18
17
12
6
6
MITRE Techniques
19
16
16
14
8
CVEs
68
68
60
58
50
48
IDS Classtypes
2
1
IDS Protocols
1
1
1
This rule performs a two-layer hunt for the ShieldBreak/RoguePlanet (CVE-2026-50656) exploit. Layer 1 detects potential privilege escalation by identifying Windows Error Reporting processes (WerFault, WerFaultSecure, or WerMgr) running as SYSTEM that initiate suspicious child processes like cmd.exe, powershell.exe, or rundll32.exe. Layer 2 identifies the presence of known exploit artifacts including 'ShieldBreak.exe', 'Warden.dll', and the 'eicar_com.zip' test file via process execution or file creation events.
This rule performs a two-layer hunt for the ShieldBreak/RoguePlanet (CVE-2026-50656) exploit. Layer 1 detects potential privilege escalation by identifying Windows Error Reporting processes (WerFault, WerFaultSecure, or WerMgr) running as SYSTEM that initiate suspicious child processes like cmd.exe, powershell.exe, or rundll32.exe. Layer 2 identifies the presence of known exploit artifacts including 'ShieldBreak.exe', 'Warden.dll', and the 'eicar_com.zip' test file via process execution or file creation events.
This rule performs a two-layer hunt for the ShieldBreak/RoguePlanet (CVE-2026-50656) exploit. Layer 1 detects potential privilege escalation by identifying Windows Error Reporting processes (WerFault, WerFaultSecure, or WerMgr) running as SYSTEM that initiate suspicious child processes like cmd.exe, powershell.exe, or rundll32.exe. Layer 2 identifies the presence of known exploit artifacts including 'ShieldBreak.exe', 'Warden.dll', and the 'eicar_com.zip' test file via process execution or file creation events.
ShieldBreak CVE-2026-50656 Cortex XDR
Cortex XDR
unsigned process loading both MpClient.dll and cldapi.dll in the same process instance. this is the core behavioral invariant of CVE-2026-50656 exploitation - MpClient is needed to trigger scan/remediation via RPC, cldapi provides the cloud filter callback that swaps file content mid-scan. neither DLL can be removed without breaking the exploit. with Cortex XDR as primary AV, Defender runs in passive mode and the exploit fails at scan stage, but the DLL load pattern still gets recorded by the agent. this rule detects the attempt, not the successful exploitation.
Detects a SYSTEM-privileged cmd.exe/powershell.exe process spawned in close temporal/process proximity to Microsoft Defender's scanning process (MsMpEng.exe), consistent with successful exploitation of the ShieldBreak zero-day (CVE-2026-50656) TOCTOU bypass. Excludes known legitimate SYSTEM shell spawns from scheduled tasks, SCCM/Intune, and PsExec-style tooling.
Detects a Windows Error Reporting (WER) crash report for MsMpEng.exe whose fault signature matches the ShieldBreak exploit crash pattern, indicating the Defender process crashed as a byproduct of the TOCTOU exploitation attempt. Excludes routine crashes tied to signature/platform updates.
Detects the compiled ShieldBreak C++ proof-of-concept exploit binary via embedded source/resource path strings and PE header, indicating local possession or execution of the CVE-2026-50656 Defender bypass PoC.
Detects loading of Warden.dll — the Defender-bypass component of the ShieldBreak exploit — when unsigned or not signed by Microsoft, excluding legitimate signed Defender platform update binaries.
Detects static file artifacts bundled with the publicly released ShieldBreak Microsoft Defender exploit kit
Detects successful SYSTEM-level privilege escalation via the ShieldBreak exploit, which bypasses the fix for CVE-2026-50656 (RoguePlanet) on fully patched Windows 10, 11, and Server 2025 systems while Microsoft Defender is enabled. Fires when ShieldBreak.exe spawns cmd.exe running as NT AUTHORITY\SYSTEM with a whoami/system confirmation, correlated with Defender activity on the host within a 5-minute window.
Detects registration of an unrecognized cloud sync provider combined with placeholder file creation within a short window, consistent with ShieldBreak's TOCTOU race staging technique. Excludes signed installs/re-registrations of known legitimate cloud sync clients (OneDrive, Dropbox, Google Drive, Box).
Detects creation and locking of a CLFS log file matching the ShieldBreak-specific naming/path pattern, used to synchronize the exploit's TOCTOU race window against Microsoft Defender. Excludes legitimate CLFS consumers (MSMQ, TxR/TxF) and Windows servicing operations.
Detects presence of ShieldBreak exploit project source, resource, and build files (e.g. ShieldBreak.cpp, ShieldBreak.vcxproj, shlbrk.ico) using exact known project artifact names, indicating local exploit development or PoC compilation activity.
Detects ntdll.dll being copied into an alternate data stream at a ShieldBreak-specific staging path, used to prepare the overwrite of a protected system DLL. Excludes legitimate backup, imaging, and EDR/forensic tooling that streams or duplicates system DLLs.
Detects Windows Defender process-level interaction consistent with the ShieldBreak exploit: MsMpEng.exe spawning an unexpected child process (excluding known-legitimate Defender helpers), or Defender's on-access scanner being triggered against unusual globalroot\BaseNamedObjects object-manager paths instead of normal filesystem paths.
Detects presence of the EICAR AV test file only when co-occurring with ShieldBreak exploit artifacts (PoC binary, build files, or Warden.dll) in the same directory or process context, indicating exploit development/testing activity rather than routine AV testing.
Detects network access to known repositories hosting the publicly disclosed ShieldBreak Microsoft Defender zero-day bypass PoC/tooling (GitHub, Project Nightcrawler, Church of Malware mirrors) via HTTP host/URI or TLS SNI matching.
Detects DNS, HTTP, and TLS access to the public code-hosting repositories publishing the ShieldBreak Microsoft Defender 0-day exploit (GitHub, git.projectnightcrawler.dev, git.churchofmalware.org).
Detects network retrieval of the ShieldBreak exploit PoC or the UnDefend companion tool from their known distribution infrastructure (git.projectnightcrawler.dev, github.com/Nightmare-Eclipse/UnDefend) via TLS SNI or HTTP host/URI matching.
Detects the ShieldBreak Defender-scan TOCTOU exploit locking an alternate data stream on the protected system DLL phoneinfo.dll immediately prior to an arbitrary write — the core privilege-escalation primitive of CVE-2026-50656. Excludes legitimate Windows Update/servicing operations.
Correlates the ShieldBreak PoC's 'Exploit succeeded' console output with a SYSTEM-privileged cmd.exe spawn in the same process session within a short window, confirming successful end-to-end exploitation of CVE-2026-50656.
Page 1 of 3




