CVE-2026-84226 OpenVPN
Detects execution of netsh.exe when launched from unexpected parent processes (tapctl.exe or openvpnserv.exe) from locations other than the standard System32 or SysWOW64 directories. This pattern is indicative of potential malicious activity or persistence via Netsh helper DLLs masquerading or executing via non-standard paths.
Microsoft Sentinel (KQL)

