Windows Defender MpClient.dll Loaded by Non-Defender Process: endpointEndpointNoneversion:1
The following analytic detects mpclient.dll, the Windows Defender client API library, being loaded by a process that is not part of the Windows Defender platform.
mpclient.dll exposes the API surface used to drive on-demand Defender scans (IOAV, MpScan). In the ShieldBreak exploit, the attacker binary loads mpclient.dll directly and calls its scan APIs against an object-manager path in order to trigger a Defender scan against attacker-controlled content as part of a race condition targeting Defender's placeholder-hydration behavior.
If confirmed malicious, this activity indicates an attempt to weaponize Windows Defender's own scanning pipeline for local privilege escalation.
Windows App Layer Protocol Wermgr Connect To NamedPipe: endpointEndpointNoneversion:11
The following analytic detects the wermgr.exe process creating or connecting to a named pipe. It leverages Sysmon EventCodes 17 and 18 to identify these actions. This activity is significant because wermgr.exe, a legitimate Windows OS Problem Reporting application, is often abused by malware such as Trickbot and Qakbot to execute malicious code. If confirmed malicious, this behavior could indicate that an attacker has injected code into wermgr.exe, potentially allowing them to communicate covertly, escalate privileges, or persist within the environment.
Windows Phantom DLL Created on Disk: endpointEndpointNoneversion:2
The following analytic detects creation of DLL files with names associated with phantom DLL hijacking opportunities.
These DLLs are usually absent from standard Windows installations, but legitimate Windows components or services may attempt to load them when they are present in expected search paths such as System32.
Phantom DLL hijacking involves placing a malicious DLL where a legitimate process will search for a non-existent dependency, allowing the attacker-controlled library to execute in that process context.
ShieldBreak is one example where the exploit redirects a privileged Defender-driven write into C:\Windows\System32\phoneinfo.dll and then triggers Windows Error Reporting so wermgr.exe loads the planted DLL at SYSTEM integrity.
If confirmed malicious, this activity can indicate preparation for code execution, persistence, or local privilege escalation through DLL search order hijacking.
Windows Process Injection Wermgr Child Process: endpointEndpointNoneversion:12
The following analytic identifies a suspicious instance of wermgr.exe spawning a child process unrelated to error or fault handling. This detection leverages data from Endpoint Detection and Response (EDR) agents, focusing on process relationships and command-line executions. This activity is significant as it can indicate Qakbot malware, which injects malicious code into wermgr.exe to evade detection and execute malicious actions. If confirmed malicious, this behavior could allow an attacker to conduct reconnaissance, execute arbitrary code, and persist within the network, posing a severe security risk.
Windows Defender Intermediary Artifact Was Observed: endpointEndpointNoneversion:1
The following analytic detects creation and removal of intermediary remediation artifacts of Windows Defender, during exploitation of ShieldCrash attacks.
Exploit abuses the race condition between file validation and its remediation performed by Windows Defender. In between these steps, ShieldCrash changes the
symbolic link to redirect the remediation process to a staging directory controlled by the attacker. This detection aims to detect creation of defender artifact,
its alternate data stream, and their subsequent removal.
Windows Wermgr Alternate Data Stream in Temp Dir: endpointEndpointNoneversion:2
The following analytic detects the wermgr.exe process creating an alternate stream in the temp directory. It leverages Sysmon EventID 15 to identify these actions.
This activity is significant because wermgr.exe is typically associated with error reporting, not file creation. Such activity is significant as it may indicate RoguePlanet malware, which creates an alternate stream in the temp directory to execute malicious code.
If confirmed malicious, this could lead to further malware infections, data exfiltration, or system compromise.
Windows Defender Threat Detected on Kernel Object Path: endpointEndpointNoneversion:1
The following analytic detects a Windows Defender malware detection or remediation event where the scanned path resolves through the NT object manager namespace (\globalroot\).
It leverages Windows Defender Operational log EventCodes 1116 and 1117 to identify this activity.
In the ShieldBreak exploit, this is how Defender is coerced into hydrating a cloud file placeholder and copying attacker content through a symbolic link chain that ultimately writes into C:\Windows\System32.
If confirmed malicious, this activity indicates an attempt to weaponize Windows Defender's own scanning pipeline for local privilege escalation.
Windows Error Report Created in ReportQueue Manually: endpointEndpointNoneversion:1
The following analytic detects a .wer file being written into the Windows Error Reporting ReportQueue directory by a process other than the standard error-reporting binaries.
Windows Error Reporting normally populates ReportQueue only through werfault.exe, werfaultsecure.exe, or wermgr.exe following an actual application crash.
In the ShieldBreak exploit, the attacker fabricates a .wer report directly and manually invokes the QueueReporting scheduled task, which causes wermgr.exe to process the report and load an attacker-planted phantom DLL at SYSTEM integrity.
If confirmed malicious, this activity indicates preparation for a local privilege escalation attempt abusing Windows Error Reporting.
Windows Wermgr Spawning System Integrity Process: endpointEndpointNoneversion:1
The following analytic detects WerMgr.exe (Windows Error Reporting) spawning a child process running at SYSTEM integrity level.
WerMgr.exe normally runs at the integrity level of the reporting user or as a background SYSTEM-owned service that does not launch interactive children.
In the ShieldBreak exploit, WerMgr.exe is manually triggered via the QueueReporting scheduled task and loads an attacker-planted phantom DLL (phoneinfo.dll), which then spawns an elevated shell.
If confirmed malicious, this activity indicates successful local privilege escalation to SYSTEM.
Executables Or Script Creation In Temp Path: endpointEndpointNoneversion:27
The following analytic identifies the creation of executables or scripts in temporary file paths on Windows systems. It leverages the Endpoint.Filesystem data set to detect files with specific extensions (e.g., .exe, .dll, .ps1) created in temporary directories (e.g., \windows\Temp\, \AppData\Local\Temp\).
This activity can be significant as adversaries often use these paths to evade detection and maintain persistence.
If confirmed malicious, this behavior could allow attackers to execute unauthorized code, escalate privileges, or persist within the environment, posing a significant security threat.
Windows Alternate Data Stream Created Over Local Share: endpointEndpointNoneversion:2
The following analytic detects the creation of an NTFS alternate data stream (ADS) accessed over a local administrative share targeting the loopback address (127.0.0.1).
It leverages Windows Security Event Logs with EventCode 5145 to identify this activity.
Legitimate local processes access files directly rather than through a local SMB share.
This behavior is a hallmark of the ShieldBreak exploit, which abuses a symbolic link swap through a loopback share to redirect a privileged, Defender-driven write into an alternate data stream on a system-owned file, ultimately landing attacker content in C:\Windows\System32.
If confirmed malicious, this activity indicates an in-progress local privilege escalation attempt and should be investigated immediately.
Windows Suspicious Process File Path: endpointEndpointNoneversion:29
The following analytic identifies processes running from file paths not typically associated with legitimate software. It leverages data from Endpoint Detection and Response (EDR) agents, focusing on specific process paths within the Endpoint data model. This activity is significant because adversaries often use unconventional file paths to execute malicious code without requiring administrative privileges. If confirmed malicious, this behavior could indicate an attempt to bypass security controls, leading to unauthorized software execution, potential system compromise, and further malicious activities within the environment.
Windows Process Execution in Temp Dir: endpointEndpointNoneversion:13
The following analytic identifies processes running from %temp% directory file paths. It leverages data from Endpoint Detection and Response (EDR) agents, focusing on specific process paths within the Endpoint data model. This activity is significant because adversaries often use unconventional file paths to execute malicious code without requiring administrative privileges. If confirmed malicious, this behavior could indicate an attempt to bypass security controls, leading to unauthorized software execution, potential system compromise, and further malicious activities within the environment.