Robuta

https://detection.fyi/sigmahq/sigma/windows/file/file_event/file_event_win_werfault_dll_hijacking/ Creation of WerFault.exe/Wer.dll in Unusual Folder | Detection.FYI Detects the creation of a file named "WerFault.exe" or "wer.dll" in an uncommon folder, which could be a sign of WerFault DLL hijacking. creationexewer