RoguePlanet Oplock on VSS-backed wermgr.exe:WDFOO ADS for Defender race condition
Detects suspicious access to wermgr.exe involving Alternate Data Streams (ADS) using the WDFOO tag, or access via Volume Shadow Copy (VSS) paths, often indicative of exploitation attempts related to CVE-2026-50656 where an adversary uses oplocks for race conditions against Windows Defender.
Splunk (SPL)

