Suspicious CTFMON Process Execution
Detects anomalous executions of ctfmon.exe that deviate from known-good parent process patterns, such as unexpected parent processes (e.g., script hosts, LOLBins) or execution from locations other than C:\Windows\System32\ctfmon.exe. This rule is designed to help identify potential masquerading or process injection associated with exploitation attempts, including CVE-2026-45586.
Microsoft Sentinel (KQL)

