diff --git a/src/windows-hardening/windows-local-privilege-escalation/kernel-race-condition-object-manager-slowdown.md b/src/windows-hardening/windows-local-privilege-escalation/kernel-race-condition-object-manager-slowdown.md
index b2380ba4312..8810b503f91 100644
--- a/src/windows-hardening/windows-local-privilege-escalation/kernel-race-condition-object-manager-slowdown.md
+++ b/src/windows-hardening/windows-local-privilege-escalation/kernel-race-condition-object-manager-slowdown.md
@@ -116,6 +116,63 @@ The results feed directly into your race orchestration strategy (e.g., number of
- When Thread A resumes and performs the privileged action, it observes stale state and performs the attacker-controlled operation.
4. **Clean up** – Delete the directory chain and symbolic links to avoid leaving suspicious artifacts or breaking legitimate IPC users.[[1]](#references)
+## Applied chain: mutable Cloud Files placeholders + Object Manager path switching
+
+[ShieldBreak](https://github.com/MSNightmare/ShieldBreak), published as a bypass for RoguePlanet (CVE-2026-50656), demonstrates a broader exploitation pattern: make a privileged scanner classify one representation of a logical file, then change both its bytes and namespace resolution before remediation uses it. The PoC combines a Cloud Files hydration TOCTOU, an Object Manager shadow-directory fallback, CLFS-generated-name capture, and a local administrative-share link to turn Defender cleanup into a protected DLL write.[[3]](#references)[[4]](#references)
+
+### 1. Substitute content through Cloud Files hydration
+
+Register an attacker-writable directory as a Cloud Files sync root, connect a `CF_CALLBACK_TYPE_FETCH_DATA` callback, and create a placeholder whose advertised size matches a deterministic detection trigger such as the EICAR ZIP. The first fetch returns the trigger and flips callback state; later fetches return the payload. After the scanner has classified the first representation, obtain the transfer key and restart hydration with payload-sized metadata, then force hydration to EOF.[[4]](#references)
+
+```cpp
+CfRegisterSyncRoot(sync_root, ®istration, &policies, flags);
+CfConnectSyncRoot(sync_root, callbacks, &state, connect_flags, &connection);
+CfCreatePlaceholders(sync_root, &placeholder, 1, 0, &created);
+// First FETCH_DATA => detection trigger; later FETCH_DATA => payload.
+CfGetTransferKey(placeholder_handle, &transfer_key);
+opInfo.Type = CF_OPERATION_TYPE_RESTART_HYDRATION;
+CfExecute(&opInfo, &restart_params);
+CfHydratePlaceholder(placeholder_handle, {0}, CF_EOF, 0, NULL);
+```
+
+The security boundary fails if scan, verdict, and remediation refer only to a pathname or placeholder identity: neither guarantees that a later hydration returns the bytes that were inspected.[[4]](#references)
+
+### 2. Switch an invariant path through a shadow-directory fallback
+
+Create a target Object Manager directory and a second directory with `NtCreateDirectoryObjectEx`, passing the target handle as its shadow/fallback directory. Put a same-named `WD_SCAN` entry in both resolution layers: the visible entry points to the normal working directory, while the fallback entry points to `\CLFS\??\`. Supply Defender only the invariant path below; deleting the visible link while the operation is active makes the same string fall through to the CLFS-backed entry.[[4]](#references)
+
+```text
+\\.\globalroot\BaseNamedObjects\Restricted\WD_SHADOW_\WD_SCAN\BERLIN
+```
+
+This is distinct from using shadow directories only to slow lookup: the attacker changes the **meaning** of a previously accepted path without modifying its string.[[4]](#references)
+
+### 3. Capture the generated name and install a filename-specific link
+
+Monitor the working directory with `ReadDirectoryChangesW`. On the first `FILE_ACTION_ADDED`, remove the visible `WD_SCAN` link to activate fallback lookup. Capture the second generated filename, open that CLFS-related file, and lock the range `0..MAXLONGLONG` with `LockFileEx`. While the privileged operation is stalled, replace `WD_SCAN` in the visible directory with a real Object Manager directory and create a child symbolic link named from the observed filename (the PoC strips its final four characters). Point it to the protected destination through local SMB:[[4]](#references)
+
+```text
+\??\UNC\127.0.0.1\C$\Windows\System32\phoneinfo.dll
+```
+
+The unprivileged process cannot write that destination itself, but Defender's SYSTEM context can traverse the loopback administrative share. Combining generated-name observation with a filename-specific Object Manager link avoids having to predict the remediation artifact in advance.[[4]](#references)
+
+### 4. Stabilize the cleanup race and trigger a privileged loader
+
+Before scanning, the PoC stores a valid PE (`ntdll.dll`) in the placeholder's `:stream` NTFS alternate data stream. After redirection creates the protected base file, it opens `phoneinfo.dll:stream` with execute access and keeps a `PAGE_EXECUTE_READ | SEC_IMAGE` mapping alive while cleanup resumes; the live file/section objects constrain deletion or replacement during the final race. The restarted hydration now returns the payload DLL rather than EICAR, so the protected base file contains attacker-controlled code.[[4]](#references)
+
+A protected write is then converted to SYSTEM execution by placing a crafted `Report.wer` under `C:\ProgramData\Microsoft\Windows\WER\ReportQueue\...` and invoking `\Microsoft\Windows\Windows Error Reporting\QueueReporting` through the Task Scheduler COM API. In this chain, privileged WER processing loads the planted `C:\Windows\System32\phoneinfo.dll`; a named-pipe connection is used as the payload execution signal.[[4]](#references)
+
+### Detection pivots
+
+Useful correlations are more specific than any single temporary filename and cover all namespace transitions in the chain:[[4]](#references)
+
+- A newly registered Cloud Files provider followed by EICAR detection and `CF_OPERATION_TYPE_RESTART_HYDRATION` on the same placeholder.
+- Object Manager paths containing `WD_TARGET_*`, `WD_SHADOW_*`, or `WD_SCAN`, especially a scan path below `\\.\globalroot\BaseNamedObjects\Restricted\`.
+- CLFS file creation followed by an exclusive whole-file lock and loopback access to `\\127.0.0.1\C$\Windows\System32\*.dll` from a privileged security process.
+- Creation of a System32 DLL together with an NTFS ADS, followed by `SEC_IMAGE` mapping of the stream.
+- An attacker-created WER queue entry followed by an unusual manual run of `\Microsoft\Windows\Windows Error Reporting\QueueReporting` and an image load of the planted DLL.
+
## Operational considerations
- **Combine primitives** – You can use a long name *per level* in a directory chain for even higher latency until you exhaust the `UNICODE_STRING` size.
@@ -134,5 +191,7 @@ The results feed directly into your race orchestration strategy (e.g., number of
- [1] [Project Zero – Windows Exploitation Techniques: Winning Race Conditions with Path Lookups](https://projectzero.google/2025/12/windows-exploitation-techniques.html)
- [2] [googleprojectzero/symboliclink-testing-tools](https://github.com/googleprojectzero/symboliclink-testing-tools)
+- [3] [MSNightmare/ShieldBreak](https://github.com/MSNightmare/ShieldBreak)
+- [4] [ShieldBreak.cpp (commit be016d8)](https://github.com/MSNightmare/ShieldBreak/blob/be016d8c18c8355a12753286c1ce9d5a48a0dab4/ShieldBreak.cpp)
{{#include ../../banners/hacktricks-training.md}}