Suspicious Child Process from ScreenConnect ClientService (CVE-2026-84869)
Detects unexpected child process execution spawned by the ScreenConnect ClientService. This activity is indicative of the exploitation of CVE-2026-84869, which allows for unauthorized file transfer and arbitrary code execution within the context of the remote support agent without requiring user interaction or confirmation.
Sigma

