ScreenConnect Client Spawning Shell Processes (CVE-2026-84869)
Detects when the ScreenConnect remote administration client process spawns common command-line or scripting interpreters. This behavior is indicative of an interactive session or remote command execution performed via the ScreenConnect tool, which is frequently abused by threat actors for lateral movement and remote control.
Cortex XDR

