
Weekly detection engineering roundup: 39 new rules and 13 updates across 8 repos target ShieldBreak exploitation, RMM abuse, macOS CVE-2026-65400, and AI agent worm propagation. Key additions this week: - Splunk added ShieldBreak exploit coverage: watch for mpclient.dll loaded outside the Defender platform, Defender events referencing \globalroot kernel object paths, and NTFS ADS creation over loopback shares (Security EventCode 5145). Companion rules flag WerMgr.exe spawning SYSTEM-integrity children and phantom DLL creation tied to CVE-2020-7315. - RMM abuse detection expanded across three repos. New Sigma rules cover Teleport Connect installer execution (Teleport Connect Setup-*.exe), registry writes under HKLM/HKCU policy paths, and DNS queries to known RMM domains. A KQL hunt correlates email bombing, Teams phishing, and subsequent RMM execution in a single query. - A KQL rule for CVE-2026-65400 on macOS hunts SSFileCopyReceiver activity, pfctl alterations, LaunchDaemon persistence, hidden root file writes, and outbound mining traffic via Defender XDR telemetry. - Python supply-chain persistence rules now track .pth file creation, http://sitecustomize.py and http://usercustomize.py drops (as seen in VIPERTUNNEL), and outbound connections during package builds. A separate rule monitors Event 4663 for reads against accessTokens.json and TokenCache.dat. #DFIR_Radar
Post summary
The post discloses detection rule details for CVE-2026-65400 without any PoC, exploit code, patch guidance, or evidence of active exploitation.
