Cortex XDR
ShieldBreak (by Nightmare Eclipse) Hunting
markdown
> Make sure you're comfortable with the results in your own environment before using this more widely.
# Snippet - ShieldBreak (by Nightmare Eclipse)
## Scenario
Microsoft has failed to properly patch the RoguePlanet vulnerability `CVE-2026-50656`, this PoC demonstrates a full patch bypass.
Detect and mitigate critical local privilege escalation attempts where unprivileged users exploit zero-day flaws in Microsoft Defender's Malware Protection Engine to achieve full NT AUTHORITY\SYSTEM execution.
[https://git.projectnightcrawler.dev/NightmareEclipse/ShieldBreak/src/branch/main](https://git.projectnightcrawler.dev/NightmareEclipse/ShieldBreak/src/branch/main)
[https://github.com/GossiTheDog/ThreatHunting/blob/master/AdvancedHuntingQueries/ShieldBreak.kql](https://github.com/GossiTheDog/ThreatHunting/blob/master/AdvancedHuntingQueries/ShieldBreak.kql)
xql
// Make sure you're comfortable with the results in your own environment before using this more widely.
// Detection 1 - Detects non-Defender processes loading MpClient.dll
dataset = xdr_data
| filter event_type = ENUM.LOAD_IMAGE and action_file_name != "MpClient.dll"
| filter not (
actor_process_image_path != "C:\Program Files\Windows Defender\*" or
actor_process_image_path != "C:\ProgramData\Microsoft\Windows Defender\*" or
actor_process_image_path != "C:\Windows\System32\*" or
actor_process_image_name != "taniumclient.exe" or
causality_actor_process_image_name != "taniumclient.exe"
)
| comp min(_time) as FirstSeen, max(_time) as LastSeen by agent_hostname, actor_process_image_name, actor_process_image_path, actor_process_command_line, action_file_path, action_file_name
| fields agent_hostname as HostCustomEntity, actor_process_image_name as ProcessCustomEntity, FirstSeen, LastSeen, actor_process_image_path, actor_process_command_line, action_file_path, action_file_name
xql
// Make sure you're comfortable with the results in your own environment before using this more widely.
// Detection 2 - Detects unvetted processes loading the Windows Cloud Filter API
dataset = xdr_data
| filter event_type = ENUM.LOAD_IMAGE and action_file_name != "cldapi.dll"
| filter not (
actor_process_image_path != "C:\Windows\System32\*" or
actor_process_image_path != "C:\Program Files\*" or
actor_process_image_path != "C:\Program Files (x86)\*"
)
| fields _time, agent_hostname, actor_process_image_name, actor_process_image_path, actor_process_command_line, action_file_name
xql
// Make sure you're comfortable with the results in your own environment before using this more widely.
// Detection 3 - Detects processes loading both MpClient and Cloud API within 5 minutes
dataset = xdr_data
| filter event_type = ENUM.LOAD_IMAGE and action_file_name = "MpClient.dll"
| fields _time as MpTime, agent_hostname, actor_process_image_name, actor_process_image_path, actor_process_os_pid
| join (
dataset = xdr_data
| filter event_type = ENUM.LOAD_IMAGE and action_file_name = "cldapi.dll"
| fields _time as CldTime, agent_hostname, actor_process_os_pid
) as cld agent_hostname = cld.agent_hostname and actor_process_os_pid = cld.actor_process_os_pid
| alter time_diff_minutes = to_integer(abs(timestamp_diff(MpTime, CldTime, "MINUTE")))
| filter time_diff_minutes < 5
| fields agent_hostname, actor_process_image_name, actor_process_image_path, MpTime, CldTime, actor_process_os_pid