ScreenConnect File Transfer Without Session Confirmation (CVE-2026-84869)

Detects instances where the ScreenConnect remote access client processes perform file creation or modification actions that are not preceded by or correlated with legitimate session activity logs (such as 'SessionConfirmed' or 'TransferFiles') within a 5-minute window. This behavior may indicate an unauthorized remote session or abuse of the remote access tool.