CVE-2026-84869 ScreenConnect auth bypass session takeover

Detects high-frequency authentication attempts originating from ScreenConnect processes on a single host within a 15-minute window. This behavior is indicative of session hijacking or authentication bypass attempts targeting ScreenConnect, such as those associated with CVE-2026-84869.