Python Spawning Curl Process (Potential CVE-2026-4372 Exploitation)

Detects a Python process spawning curl to make outbound web requests. This behavior aligns with the PoC for CVE-2026-4372 (HuggingFace Transformers RCE), where Python sub-processes curl to exfiltrate credentials.

Microsoft Sentinel (KQL)