Quick Share / Nearby Sharing Unexpected Child Process Spawning
Detects instances where Windows NearShare or QuickShare utilities spawn child processes that are not part of their standard operational or helper suite (e.g., conhost.exe, WerFault.exe, svchost.exe). This pattern is often indicative of process injection, living-off-the-land techniques, or unauthorized activity masquerading as legitimate Windows sharing services.
Microsoft Sentinel (KQL)

