ScreenConnect CVE-2026-84869 Auth Bypass Exploitation
Detects the execution of common command-line or scripting interpreters (cmd, powershell, cscript, etc.) spawned by the ScreenConnect remote administration client. This is a common pattern used by attackers leveraging legitimate remote access tools for post-exploitation activities and lateral movement.
SentinelOne

