CVE-2026-84869 ScreenConnect auth bypass session takeover
Detects high-frequency authentication attempts originating from ScreenConnect processes on a single host within a 15-minute window. This behavior is indicative of session hijacking or authentication bypass attempts targeting ScreenConnect, such as those associated with CVE-2026-84869.
YARA-L

