Potential Web Server Exploitation via Suspicious Child Process
Detects potentially suspicious command or script execution directly initiated by an IIS worker process (w3wp.exe) on a specified device and date. The query identifies web-server processes spawning command shells, PowerShell, script interpreters, download utilities, or LOLBins, which may indicate web-shell execution, vulnerable application exploitation, or unauthorized server-side command execution.
Microsoft Sentinel (KQL)

