ProxyLogon (CVE-2021-26855) Exploitation - w3wp.exe Spawning Suspicious Children

Detects anomalous child processes spawned by the Microsoft Exchange IIS worker process (w3wp.exe). This activity is often observed during post-exploitation phases of vulnerabilities like ProxyLogon (CVE-2021-26855), where attackers attempt to gain code execution by spawning command shells or administrative tools from the web server process.

Sigma