RoguePlanet CVE-2026-50656: SYSTEM Shell Spawned via MsMpEng.exe TOCTOU

Detects the execution of interactive shell or scripting processes (e.g., cmd.exe, powershell.exe, wscript.exe) directly or indirectly spawned by the Microsoft Defender service (MsMpEng.exe). The rule identifies processes running at SYSTEM integrity in an interactive user session, which is indicative of a TOCTOU exploit against the Defender quarantine pipeline.