Suspicious Child Process of SAP NetWeaver — Detection Rule

Detects suspicious child processes spawned by SAP NetWeaver that could indicate potential exploitation of vulnerability that allows arbitrary execution via webshells such as CVE-2025-31324.

Read the full analysis on IntelFusions