Unauthorized file execution via ScreenConnect session (CVE-2026-84869)
Detects unauthorized child processes spawned by ScreenConnect client binaries. The rule specifically looks for files created or modified within 60 seconds prior to execution, which is indicative of attackers leveraging an authentication bypass vulnerability (CVE-2026-84869) to transfer and execute malicious payloads via an active remote access session without requiring additional user interaction or authentication.
Splunk (SPL)

