RoguePlanet: QueueReporting Scheduled Task Abused to Spawn SYSTEM Shell via wermgr.exe
Detects instances where wermgr.exe, typically used for Windows Error Reporting (WER), spawns interactive command-line interfaces such as cmd.exe, powershell.exe, or others. This behavior is indicative of exploitation (such as CVE-2026-50656) where an attacker has redirected a scheduled task to execute malicious code under SYSTEM integrity, masquerading as the wermgr.exe process.
CQL

