Cloudflared Persistence and svchost.exe Masquerading Post-Exploitation
Detects post-exploitation persistence artifacts on Windows endpoints managed by N-able N-central consistent with abuse of CVE-2026-18577, including a new Windows service named Cloudflared, registry Services key creation for Cloudflared, a file named svchost.exe written under a user's Documents folder, or process execution of cloudflared.exe or a Documents-located svchost.exe.
Sigma

