RoguePlanet Exploit Staging: RP_UUID wermgr.exe or wdtest_temp in TEMP
Detects the creation of specific file and directory structures under the %TEMP% directory associated with the RoguePlanet (CVE-2026-50656) exploit. The exploit utilizes a UUID-named directory prefixed with 'RP_' to stage components, including wermgr.exe and wdtest_temp, required for a junction swap attack against Microsoft Defender. The detection excludes known system processes that might access the temporary folder.
Sigma

