WER Task SYSTEM Execution Loading Recently Planted System32 DLL

Detects instances where WerFault.exe or WerMgr.exe, running with SYSTEM privileges, loads a DLL file from the Windows\System32 directory that was created within 10 minutes of the image load event. This behavior is indicative of potential DLL side-loading or hijack techniques used to achieve privilege escalation.