Detections
Explore public detection logic contributed by the community across SIEM and rule languages.
48 detections
Filters
Last updated
All Time
Detection languages
12
11
7
5
5
Contributors
23
20
1
1
1
Categories
13
11
11
8
7
Platforms
45
3
Products / Services
18
17
12
6
6
MITRE Techniques
19
16
16
14
8
CVEs
68
68
60
58
49
48
IDS Classtypes
2
1
IDS Protocols
1
1
1
Detects the creation of specific file and directory structures under the %TEMP% directory associated with the RoguePlanet (CVE-2026-50656) exploit. The exploit utilizes a UUID-named directory prefixed with 'RP_' to stage components, including wermgr.exe and wdtest_temp, required for a junction swap attack against Microsoft Defender. The detection excludes known system processes that might access the temporary folder.
Detects suspicious activities related to the RoguePlanet vulnerability (CVE-2026-50656), characterized by the creation of temporary directory structures in user folders, mounting of disk images (ISO/VHD) from user-accessible paths, and subsequent execution of binaries from these temporary workspaces.
Detects anomalous, high-volume file creation patterns in temp directories characterized by UUID-style filenames from non-system processes. This behavior is indicative of a multi-threaded I/O saturation technique used by the RoguePlanet exploit to create a race condition (TOCTOU) against Microsoft Defender (MsMpEng.exe).
Detects anomalous activity associated with the RoguePlanet (CVE-2026-50656) exploit. The rule identifies suspicious file operations by MsMpEng.exe within temporary staging directories (RP_<UUID>), execution of non-Microsoft signed binaries from these staging paths, and unexpected file activity involving 'wdtest_temp' paths, which are indicative of an NTFS junction swap exploit sequence.
Detects suspicious access to wermgr.exe involving Alternate Data Streams (ADS) using the WDFOO tag, or access via Volume Shadow Copy (VSS) paths, often indicative of exploitation attempts related to CVE-2026-50656 where an adversary uses oplocks for race conditions against Windows Defender.
Detects the creation of UUID-named files within RoguePlanet staging directories (RP_<UUID>) under the %TEMP% path. This activity is indicative of Poseidon thread I/O saturation, a technique used to artificially extend the TOCTOU (Time-of-Check to Time-of-Use) race condition window against the Microsoft Defender service (MsMpEng.exe) as part of an exploit for CVE-2026-50656.
Page 3 of 3
