RoguePlanet Named Pipe \pipe\RoguePlanet Creation for SYSTEM Session Verification
Detects the creation of the named pipe '\pipe\RoguePlanet', which is specifically utilized by the RoguePlanet CVE-2026-50656 exploit. The exploit uses this pipe for synchronization during a TOCTOU race condition against MsMpEng.exe. Once the race is won, a SYSTEM-level payload (typically masquerading as a child process of wermgr.exe) uses this pipe to verify the originating session and subsequently spawn an interactive shell as NT AUTHORITY\SYSTEM. This pipe name is unique to this exploit and not used by legitimate software.
Sigma

