Detections
Explore public detection logic contributed by the community across SIEM and rule languages.
48 detections
Filters
Last updated
All Time
Detection languages
12
11
7
5
5
Contributors
23
20
1
1
1
Categories
13
11
11
8
7
Platforms
45
3
Products / Services
18
17
12
6
6
MITRE Techniques
19
16
16
14
8
CVEs
68
68
60
58
49
48
IDS Classtypes
2
1
IDS Protocols
1
1
1
Detects execution of whoami.exe as NT AUTHORITY\SYSTEM within a short window of, and parented by, a suspicious SYSTEM-privileged shell spawn — a common post-exploitation confirmation step following successful ShieldBreak exploitation. Standalone whoami execution is excluded by design.
Detects the full technical staging sequence unique to the ShieldBreak CLFS time-of-check-to-time-of-use (TOCTOU) technique: cloud provider registration, WD_TARGET/WD_SHADOW object-manager directory creation, WD_SCAN object-link creation under the normal and CLFS namespaces, ntdll.dll copy into a BERLIN alternate data stream, the link-deletion/CLFS-log-lock race sequence, and the final phoneinfo.dll:stream lock confirming the file-overwrite primitive succeeded.
Detects creation of restricted object manager namespace objects (WD_TARGET_/WD_SHADOW_/WD_SCAN) used to hijack Microsoft Defender's on-access scan target as part of the ShieldBreak exploit, excluding objects created by signed Microsoft/Defender processes.
This rule detects potential Local Privilege Escalation (LPE) activity related to a threat dubbed 'Rogue Planet'. It monitors for the creation of temporary files in the local AppData directory with a 'RP_' prefix and the usage of a specific named pipe named 'RoguePlanet'. The rule further isolates suspicious behavior by identifying processes that are not the standard Windows Error Reporting Manager (wermgr.exe) executing from its legitimate path.
Detects Microsoft Defender service (MsMpEng.exe) spawning common interactive or scripting processes (such as cmd.exe, powershell.exe, etc.) while running as SYSTEM. This behavior is highly irregular for an antivirus engine and is characteristic of exploit-based process hollowing or quarantine pipeline abuse, as observed in CVE-2026-50656.
Detects the creation of an NTFS Alternate Data Stream named :WDFOO in temporary staging directories, often associated with wermgr.exe and subsequent Windows Defender scans. This behavior is indicative of a TOCTOU (Time-of-Check Time-of-Use) exploitation chain, specifically linked to the RoguePlanet exploit targeting CVE-2026-50656, where EICAR test strings are used to manipulate anti-virus detection flows.
Detects the creation of working directories in temporary locations matching the RoguePlanet exploit staging pattern, specifically associated with CVE-2026-50656 (Nightmare Eclipse). The rule identifies the creation of directories containing fake System32 subdirectories or suspicious files (wermgr.exe) used in a TOCTOU (Time-of-Check Time-of-Use) exploit chain against MsMpEng.exe.
Detects the creation of or connection to the specific named pipe '\\pipe\\RoguePlanet', which is used as a synchronization and callback channel by the Nightmare Eclipse RoguePlanet exploit (CVE-2026-50656). This exploit leverages the named pipe to facilitate communication between a low-privileged exploit process and a SYSTEM-level Windows Error Reporting (WER) task payload during a local privilege escalation attempt.
Detects the creation of the named pipe '\pipe\RoguePlanet', which is specifically utilized by the RoguePlanet CVE-2026-50656 exploit. The exploit uses this pipe for synchronization during a TOCTOU race condition against MsMpEng.exe. Once the race is won, a SYSTEM-level payload (typically masquerading as a child process of wermgr.exe) uses this pipe to verify the originating session and subsequently spawn an interactive shell as NT AUTHORITY\SYSTEM. This pipe name is unique to this exploit and not used by legitimate software.
Detects unauthorized child process creation by the Windows Error Reporting Manager (wermgr.exe). The rule identifies scenarios where wermgr.exe, executed under the SYSTEM context via the QueueReporting scheduled task (often abused in the RoguePlanet exploit chain), spawns interactive shells or command processors like cmd.exe, powershell.exe, or cscript.exe. Legitimate instances of wermgr.exe do not spawn interactive user interfaces or shells.
Detects the abuse of the Windows Error Reporting (WER) service mechanism, specifically targeting the 'QueueReporting' scheduled task. Attackers may employ junction-based path redirection to execute a malicious wermgr.exe binary located outside of the standard system directory. The rule identifies instances where wermgr.exe is running from non-standard locations, or running at SYSTEM integrity level spawned by standard task-related parent processes, which indicates a potential privilege escalation or persistence attempt (linked to CVE-2026-50656).
Detects instances where wermgr.exe, typically used for Windows Error Reporting (WER), spawns interactive command-line interfaces such as cmd.exe, powershell.exe, or others. This behavior is indicative of exploitation (such as CVE-2026-50656) where an attacker has redirected a scheduled task to execute malicious code under SYSTEM integrity, masquerading as the wermgr.exe process.
Detects the creation of specific staging directories prefixed with 'RP_' in user temporary directories, containing 'System32' or 'wdtest_temp' subdirectories. This pattern is characteristic of an NTFS junction swap exploitation technique used to target Windows Defender quarantine artifact placement as part of the CVE-2026-50656 vulnerability.
Detects unauthorized execution of wermgr.exe from suspicious paths or spawned by Task Scheduler service (svchost.exe/taskeng.exe) with non-standard parent processes. This behavior is indicative of privilege escalation attempts where an unprivileged process leverages the Windows Error Reporting (WER) QueueReporting scheduled task to execute a malicious payload in the context of the SYSTEM account.
Detects activity associated with the RoguePlanet exploit, which involves creating EICAR content and NTFS Alternate Data Streams (ADS) within specific staging directories (wdtest_temp or RP_<UUID>). This behavior is intended to trigger Windows Defender scans and induce a TOCTOU race condition (CVE-2026-50656) by manipulating file operations near the wermgr.exe process.
Detects malicious activity related to the 'RoguePlanet' exploit (referencing CVE-2026-50656) which involves manipulating NTFS junctions to redirect system file operations. The rule monitors for specific staging directory patterns (RP_<UUID>), the creation of named pipes associated with RoguePlanet, and the execution of suspicious binaries or staging of files in system paths.
Detects unauthorized processes attempting to access 'wermgr.exe' via a Volume Shadow Copy Service (VSS) device path. This behavior is associated with the RoguePlanet exploit chain (CVE-2026-50656), which leverages VSS to bypass file system protections for TOCTOU (Time-of-Check to Time-of-Use) exploitation. Legitimate system and backup processes are excluded.
Detects the spawning of conhost.exe as a child process of wermgr.exe, an anomalous behavior indicative of the RoguePlanet exploit chain (CVE-2026-50656) which uses a Defender quarantine pipeline junction hijack to replace the legitimate Windows Error Reporting manager. Standard operations of the legitimate wermgr.exe process do not involve launching interactive console hosts.
Detects the execution of interactive shell or scripting processes (e.g., cmd.exe, powershell.exe, wscript.exe) directly or indirectly spawned by the Microsoft Defender service (MsMpEng.exe). The rule identifies processes running at SYSTEM integrity in an interactive user session, which is indicative of a TOCTOU exploit against the Defender quarantine pipeline.
Detects the creation of an NTFS Alternate Data Stream (ADS) named :WDFOO on the wermgr.exe process within RP_* staged directories. This behavior is a specific indicator of the RoguePlanet exploit (CVE-2026-50656), which leverages an ADS write to trigger a Microsoft Defender on-access scan and facilitate a TOCTOU (Time-of-Check to Time-of-Use) race condition for privilege escalation or exploitation.
Detects a user-mode process attempting to set an opportunistic lock (oplock) on wermgr.exe within a Volume Shadow Copy (VSS) snapshot. This behavior is associated with the RoguePlanet exploit chain (CVE-2026-50656), which leverages VSS snapshots and file locking to trigger a TOCTOU race condition against the Microsoft Defender (MsMpEng.exe) scanner.
Page 2 of 3


