RoguePlanet: QueueReporting Task Abuse Spawning wermgr.exe as SYSTEM (CVE-2026-50656)

Detects the abuse of the Windows Error Reporting (WER) service mechanism, specifically targeting the 'QueueReporting' scheduled task. Attackers may employ junction-based path redirection to execute a malicious wermgr.exe binary located outside of the standard system directory. The rule identifies instances where wermgr.exe is running from non-standard locations, or running at SYSTEM integrity level spawned by standard task-related parent processes, which indicates a potential privilege escalation or persistence attempt (linked to CVE-2026-50656).