Potentially Suspicious Child Processes Spawned by ConHost — Detection Rule

Detects suspicious child processes related to Windows Shell utilities spawned by `conhost.exe`, which could indicate malicious activity using trusted system components.

Read the full analysis on IntelFusions