Suspicious CrushFTP Child Process

Last updated on:

In this page

About the rule

Rule Type

Standard

Rule Description

Detects suspicious child processes spawned by the CrushFTP service, indicating potential remote code execution exploitation (e.g., CVE-2025-31161)

Severity

Trouble

Detection

Execution Mode

realtime

Log Sources

Windows

Author

@Craig Sweeney, Matt Anderson, Jose Oregon, Tim Kasper, Faith Stratton, Samantha Shaw, Swachchhanda Shrawan Poudel (Nextron Systems)