IIS w3wp.exe spawning abnormal children (ProxyLogon post-exploit)
Detects instances where the IIS worker process (w3wp.exe) spawns common command-line or system utilities often used for post-exploitation activities, specifically when command-line arguments contain references to 'MSExchange' or 'Exchange'. This behavior is frequently associated with exploitation attempts against Microsoft Exchange servers, such as the ProxyLogon chain, where a web shell or other malicious script might be used to execute commands via the IIS process.
SentinelOne

