Ransomware Series: Exploitation of Public-Facing VPN/Firewall/Backup Appliances

Detects the execution of suspicious child processes (e.g., cmd.exe, powershell.exe, bash, wget) spawned by processes associated with public-facing appliances like Fortinet SSL-VPN, Veeam Backup & Replication, Citrix ADC, and cPanel/WHM. This behavior is often indicative of exploitation of public-facing applications (T1190) for initial access, frequently associated with ransomware actors targeting unpatched infrastructure.