heroui logo

Windows Defender Intermediary Artifact Was Observed

Splunk Security Content

View Source
Summary
This anomaly rule detects creation and removal of intermediary Windows Defender remediation artifacts during ShieldCrash exploitation. It monitors Defender remediation activity via Sysmon events (Event IDs 11, 15, and 23) associated with Defender processes (System or msmpeng.exe) running under the SYSTEM user. The rule watches for new TargetFilename artifacts and their subsequent deletion/remediation, while excluding benign paths (e.g., Windows\Temp) and files tied to Zone.Identifier or SmartScreen. It aggregates results by destination process and requires multiple distinct TargetFilename values and Event IDs to flag potential remediation tampering. The detection signals potential Defender remediation interference used to pivot to a staging directory controlled by an attacker, a behavior consistent with privilege-escalation attempts in ShieldCrash scenarios. While not definitive, it provides a focused indicator for threat hunting and incident response, prompting correlation with related signals (e.g., suspicious process behavior, anomalous file streams, or privilege escalation activity). Implementation assumes Sysmon data ingested via the latest Sysmon Technical Add-on and configuration that captures file creation, deletion, and alternate data streams, with monitored paths configured for Defender remediation artifacts.
Categories
  • Endpoint
  • Windows
Data Sources
  • Process
  • File
ATT&CK Techniques
  • T1068
Created: 2026-10-01