Potential Exploitation of CrushFTP RCE Vulnerability (CVE-2025-54309) — Detection Rule

Detects suspicious child processes created by CrushFTP. It could be an indication of exploitation of a RCE vulnerability such as CVE-2025-54309.

Read the full analysis on IntelFusions