Suspicious Child Process of SAP NetWeaver - Linux — Detection Rule

Detects suspicious child processes spawned by SAP NetWeaver on Linux systems that could indicate potential exploitation of vulnerability that allows arbitrary execution via webshells such as CVE-2025-31324.

Read the full analysis on IntelFusions