Back to results

Windows Defender Intermediary Artifact Was Observed

The following analytic detects creation and removal of intermediary remediation artifacts of Windows Defender, during exploitation of ShieldCrash attacks. Exploit abuses the race condition between file validation and…

Description

The following analytic detects creation and removal of intermediary remediation artifacts of Windows Defender, during exploitation of ShieldCrash attacks. Exploit abuses the race condition between file validation and its remediation performed by Windows Defender. In between these steps, ShieldCrash changes the symbolic link to redirect the remediation process to a staging directory controlled by the attacker. This detection aims to detect creation of defender artifact, its alternate data stream, and their subsequent removal.

Detection logic

Detection requirements

Platform
ContainersLinuxmacOSWindows

The rule states no platform. This is derived from the ATT&CK technique it maps to.

Known benign triggers

  • Remediation of various container files, such as archives, might also lead to creation various defender artifacts SmartScreen interferes with the remediation process, potentially causing additional defender artifacts to be created.

Detections can measure how the public catalogue is used — which detections people look for, and which pages bring them here. It sets a cookie that recognises this browser for 180 days. It is never linked to an account and never follows you to other sites. Privacy notice