RoguePlanet EICAR ADS Write to :WDFOO Stream in RP_* Temp Directory
Detects the creation of an NTFS Alternate Data Stream named :WDFOO in temporary staging directories, often associated with wermgr.exe and subsequent Windows Defender scans. This behavior is indicative of a TOCTOU (Time-of-Check Time-of-Use) exploitation chain, specifically linked to the RoguePlanet exploit targeting CVE-2026-50656, where EICAR test strings are used to manipulate anti-virus detection flows.
Microsoft Sentinel (KQL)

