ScreenConnect Unconfirmed Remote File Execution (CVE-2026-84869)

Detects suspicious process execution spawned by ScreenConnect client processes, which may indicate abuse of remote access sessions for arbitrary command execution. This includes both direct child processes of ScreenConnect client binaries and execution of binaries staged within known ScreenConnect working and temporary directories.