Windows Suspicious Burst of Password Changes: endpointEndpointNoneversion:1
A regular user account performed rapid, repeated password changes across multiple local accounts within a 2-second window.
This pattern is consistent with automated credential manipulation tools that cycle account passwords to deny access to defenders or escalate privileges The speed and volume of changes indicates scripted or tooled activity rather than manual administration, as legitimate password resets do not occur at machine speed across multiple accounts simultaneously.
Windows Suspicious Defender Update Activity in INetCache: endpointEndpointNoneversion:2
Detects a non-Defender process writing mpam-fe*.exe to the Windows Internet Cache (INetCache).
BlueHammer downloads the WD signature update package directly using WinINet as a low-privileged user.
The [1].exe naming suffix is produced by Windows HTTP caching and is a reliable artifact of this download method.
Windows Suspicious Defender Engine or Signature Files Created: endpointEndpointNoneversion:1
Detects Windows Defender engine (mpengine.dll) or signature database files (*.vdm) being created by any process that is not a Windows Defender component.
BlueHammer extracts these files from the downloaded mpam-fe update package into a UUID-named subdirectory of %TEMP% as part of staging the TOCTOU privilege escalation.
Windows Admin Password Changed by Non-Admin: endpointEndpointNoneversion:2
The following analytic detects when a unprivileged user changes an Admin accounts password. This is a common artifact of successful exploitation of the BlueHammer Windows Defender privilege escalation. The attacker's process momentarily changes the passwords of high-value local accounts including the built-in Administrator to spawn an authenticated shell session, then immediately reverts the passwords to avoid detection. This uses EventID 4723 to log this activity.
Windows Cloud Files Filter Loaded by Uncommon Process: endpointEndpointNoneversion:1
The following analytic detects cldapi.dll being loaded by a process not associated with legitimate cloud sync activity.
The Windows Cloud Files API (cldapi.dll) is abused by several local privilege escalation exploits.
Windows Non-System Process Querying Definition Update: endpointEndpointNoneversion:1
Detects DNS queries to definitionupdates.microsoft.com or the go.microsoft.com fwlink redirect used for WD update downloads, when the querying process is not a Windows system component. BlueHammer utilizes these definition updates as part of its exploit chain.
Windows MsMpEng Writing to System32: endpointEndpointNoneversion:1
Detects MsMpEng.exe creating a file in C:\\Windows\\System32\\.
This should never happen under normal operation Windows Defender does not install kernel drivers at runtime.
In the BlueHammer exploit, the TOCTOU race causes MsMpEng (SYSTEM) to write the attacker's driver payload directly into the drivers directory.