Shell Process Spawned by Web Server Process - Possible RCE
Detects web server processes (e.g., httpd, nginx) spawning common shell interpreters (sh, bash, cmd.exe) that execute suspicious commands often used in reconnaissance or download stages of an attack, such as 'whoami', 'wget', or 'curl'. This behavior is characteristic of an exploited web application being used as a staging or command-and-control pivot point.
SentinelOne

