Suspicious Child Process from Exchange w3wp.exe Following ProxyLogon-style Explo

Detects the spawning of suspicious processes like cmd, powershell, or certutil by the Exchange Server's web worker process (w3wp.exe), which is a common indicator of post-exploitation activity following an initial web vulnerability exploitation, such as ProxyLogon.

Sigma