logo

Detection Logic Bugs, Developing Context to Bypass MiniPlasma Rules

ID: e2907f9e-69ea-5d82-85f1-df222910a852

STIX ID: report--e2907f9e-69ea-5d82-85f1-df222910a852

Feed Name: Detect FYI

Threat Score
75/100

Date Published: 2026-05-23

Date Updated: 2026-05-23

Author: Nikolas Bielski

...
...

This report examines how the GreenPlasma/MiniPlasma UAC escalation exploits a predictable shared-memory object path and attacker-planted symbolic links to gain SYSTEM privileges and shows how brittle detection rules (e.g., string-matching on conhost.exe) can be bypassed via process cloning and context manipulation; it recommends focusing on reliable IOCs such as volatile registry artifacts (CloudFiles\BlockedApps with SymbolicLinkValue pointing to Policies\System) and applies an ADE3 taxonomy for context-development detection bugs.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.