NW.js browser process launching apps with synthetic input injection
Detects instances where the NW.js (Node-Webkit) framework binaries (nw.exe, node.exe) spawn common command-line interpreters or script-hosting utilities (e.g., cmd.exe, powershell.exe, wscript.exe) while executing associated application files like main.js or nw.pak. This behavior is indicative of potential exploitation of a browser-based application to gain shell access or execute arbitrary code on the host system.
Microsoft Sentinel (KQL)

