RoguePlanet RP_UUID Staging Dir with Fake System32 Under %TEMP%
Detects the creation of working directories in temporary locations matching the RoguePlanet exploit staging pattern, specifically associated with CVE-2026-50656 (Nightmare Eclipse). The rule identifies the creation of directories containing fake System32 subdirectories or suspicious files (wermgr.exe) used in a TOCTOU (Time-of-Check Time-of-Use) exploit chain against MsMpEng.exe.
Microsoft Sentinel (KQL)

