RoguePlanet wermgr.exe Masquerade - conhost.exe Spawned as Child Process

Detects the spawning of conhost.exe as a child process of wermgr.exe, an anomalous behavior indicative of the RoguePlanet exploit chain (CVE-2026-50656) which uses a Defender quarantine pipeline junction hijack to replace the legitimate Windows Error Reporting manager. Standard operations of the legitimate wermgr.exe process do not involve launching interactive console hosts.