Detections

Explore public detection logic contributed by the community across SIEM and rule languages.

48 detections

Detects the creation of specific file and directory structures under the %TEMP% directory associated with the RoguePlanet (CVE-2026-50656) exploit. The exploit utilizes a UUID-named directory prefixed with 'RP_' to stage components, including wermgr.exe and wdtest_temp, required for a junction swap attack against Microsoft Defender. The detection excludes known system processes that might access the temporary folder.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
3 months ago
003
Detects suspicious activities related to the RoguePlanet vulnerability (CVE-2026-50656), characterized by the creation of temporary directory structures in user folders, mounting of disk images (ISO/VHD) from user-accessible paths, and subsequent execution of binaries from these temporary workspaces.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
3 months ago
103
Detects anomalous, high-volume file creation patterns in temp directories characterized by UUID-style filenames from non-system processes. This behavior is indicative of a multi-threaded I/O saturation technique used by the RoguePlanet exploit to create a race condition (TOCTOU) against Microsoft Defender (MsMpEng.exe).
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
3 months ago
002
Detects anomalous activity associated with the RoguePlanet (CVE-2026-50656) exploit. The rule identifies suspicious file operations by MsMpEng.exe within temporary staging directories (RP_<UUID>), execution of non-Microsoft signed binaries from these staging paths, and unexpected file activity involving 'wdtest_temp' paths, which are indicative of an NTFS junction swap exploit sequence.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
3 months ago
102
Detects suspicious access to wermgr.exe involving Alternate Data Streams (ADS) using the WDFOO tag, or access via Volume Shadow Copy (VSS) paths, often indicative of exploitation attempts related to CVE-2026-50656 where an adversary uses oplocks for race conditions against Windows Defender.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
3 months ago
001
Detects the creation of UUID-named files within RoguePlanet staging directories (RP_<UUID>) under the %TEMP% path. This activity is indicative of Poseidon thread I/O saturation, a technique used to artificially extend the TOCTOU (Time-of-Check to Time-of-Use) race condition window against the Microsoft Defender service (MsMpEng.exe) as part of an exploit for CVE-2026-50656.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
3 months ago
000
Page 3 of 3