RoguePlanet: wermgr.exe SYSTEM Execution via WER QueueReporting Task COM Trigger
Detects unauthorized execution of wermgr.exe from suspicious paths or spawned by Task Scheduler service (svchost.exe/taskeng.exe) with non-standard parent processes. This behavior is indicative of privilege escalation attempts where an unprivileged process leverages the Windows Error Reporting (WER) QueueReporting scheduled task to execute a malicious payload in the context of the SYSTEM account.
Cortex XDR

