RoguePlanet RP_UUID Staging Dir with Fake System32 Under %TEMP%

Detects the creation of working directories in temporary locations matching the RoguePlanet exploit staging pattern, specifically associated with CVE-2026-50656 (Nightmare Eclipse). The rule identifies the creation of directories containing fake System32 subdirectories or suspicious files (wermgr.exe) used in a TOCTOU (Time-of-Check Time-of-Use) exploit chain against MsMpEng.exe.