Sub-Store zero-day browser-to-localhost RCE via /api/preview/sub
Detects potential remote code execution (RCE) attempts targeting vulnerable Sub-Store instances (versions < 2.38.2). The detection identifies web browsers making network connections to local ports (38324) associated with Sub-Store, followed by the spawning of shell processes (cmd, powershell, bash, sh) by the Node.js process hosting the application.
Microsoft Sentinel (KQL)

