RoguePlanet: MsMpEng.exe Spawning Unexpected Child Processes (CVE-2026-50656)
Detects Microsoft Defender service (MsMpEng.exe) spawning common interactive or scripting processes (such as cmd.exe, powershell.exe, etc.) while running as SYSTEM. This behavior is highly irregular for an antivirus engine and is characteristic of exploit-based process hollowing or quarantine pipeline abuse, as observed in CVE-2026-50656.
Microsoft Sentinel (KQL)

