Anomalous vmware-vmx.exe child process (possible CVE-2026-59346 escape)
Detects anomalous child process creation (e.g., cmd.exe, powershell.exe, rundll32.exe) spawned by the VMware host process 'vmware-vmx.exe'. This behavioral pattern is a high-confidence indicator of potential guest-to-host virtual machine escape, specifically monitoring for activity associated with vulnerabilities like CVE-2026-59346.
Microsoft Sentinel (KQL)

