CVE-2026-69730 Windows DNS Server RCE Vulnerability

This query provides high-fidelity, post-exploitation hunting for CVE-2026-69730 by catching unauthorized child processes spawned from the Windows DNS Server engine (dns.exe). Because dns.exe runs natively as NT AUTHORITY\SYSTEM and almost never executes external binaries during normal operations, filtering out known OS noise (conhost.exe and werfault.exe) flags potential RCE breakouts and privilege escalation with near-zero false positives.