ScreenConnect File Transfer via CVE-2026-84869 Auth Bypass

Detects unauthorized file write operations performed by ScreenConnect client or service processes into client/transfer directories. This activity is indicative of exploitation attempts, specifically CVE-2026-84869, which allows for unauthorized file transfers and potential remote code execution via active ScreenConnect sessions without user confirmation.