SYSTEM-level RMM client (ScreenConnect/LogMeIn) spawns PowerShell

Detects the execution of PowerShell from processes associated with legitimate Remote Monitoring and Management (RMM) tools (such as ScreenConnect or LogMeIn) running under the SYSTEM account. This behavior is indicative of an attacker who has gained access to an RMM tenant and is using an interactive session to execute commands, perform reconnaissance, or deploy further malicious payloads.