RoguePlanet EICAR Write and ADS Creation in RP_ Temp Staging Directory
Detects activity associated with the RoguePlanet exploit, which involves creating EICAR content and NTFS Alternate Data Streams (ADS) within specific staging directories (wdtest_temp or RP_<UUID>). This behavior is intended to trigger Windows Defender scans and induce a TOCTOU race condition (CVE-2026-50656) by manipulating file operations near the wermgr.exe process.
SentinelOne

