CVE-2020-0688 Exchange ECP Exploitation via w3wp.exe Child Process
Detects Microsoft Exchange Control Panel (ECP) worker process (w3wp.exe) spawning suspicious child processes (e.g., cmd.exe, powershell.exe, mshta.exe) that are commonly associated with the exploitation of CVE-2020-0688. This vulnerability involves unsafe deserialization within the Exchange ECP ViewState handling, which allows an attacker to execute arbitrary code with SYSTEM privileges.
Sigma

