RoguePlanet EICAR ADS Write to RP_* Temp Directory to Trigger Defender Scan

Detects the creation of an NTFS Alternate Data Stream (ADS) named :WDFOO on the wermgr.exe process within RP_* staged directories. This behavior is a specific indicator of the RoguePlanet exploit (CVE-2026-50656), which leverages an ADS write to trigger a Microsoft Defender on-access scan and facilitate a TOCTOU (Time-of-Check to Time-of-Use) race condition for privilege escalation or exploitation.