Detects Trickbot malware process tree pattern in which "rundll32.exe" is a parent of "wermgr.exe"
Read the full analysis on IntelFusions