Web Service Account Spawning Shell Process (Edge Appliance/ERP Exploitation)
Detects web application server processes (such as IIS, Apache, Tomcat, Java, Nginx, or Node.js) spawning command-line interpreters or system utilities. This behavior is frequently associated with webshell execution or post-exploitation activities following the exploitation of a public-facing application, often seen in VPN or enterprise software compromises.
Sigma

