RoguePlanet CVE-2026-50656: Oplock on VSS-backed wermgr.exe by User-Mode Process

Detects a user-mode process attempting to set an opportunistic lock (oplock) on wermgr.exe within a Volume Shadow Copy (VSS) snapshot. This behavior is associated with the RoguePlanet exploit chain (CVE-2026-50656), which leverages VSS snapshots and file locking to trigger a TOCTOU race condition against the Microsoft Defender (MsMpEng.exe) scanner.