RoguePlanet CVE-2026-50656 VSS NtCreateFile Access to wermgr.exe

Detects unauthorized processes attempting to access 'wermgr.exe' via a Volume Shadow Copy Service (VSS) device path. This behavior is associated with the RoguePlanet exploit chain (CVE-2026-50656), which leverages VSS to bypass file system protections for TOCTOU (Time-of-Check to Time-of-Use) exploitation. Legitimate system and backup processes are excluded.