JetBrains TeamCity Suspicious Command Execution
Detects suspicious command-line activity originating from TeamCity service processes on Windows. The rule looks for unexpected child processes (e.g., cmd.exe, powershell.exe, curl.exe) initiated by the TeamCity server or associated Java processes, which may indicate exploitation of an unauthenticated remote code execution vulnerability.
Cortex XDR

