Detecting T1055 Process Injection With Sysmon

Detect process injection techniques (T1055) including classic DLL injection, process hollowing, and APC injection by analyzing Sysmon events for cross-process memory operations, remote thread creation, and anomalous DLL loading patterns.

26zl Updated

File contents

26zl/cybersec-toolkit/tree/main/.claude/skills/detecting-t1055-process-injection-with-sysmon commit b9c2e90973

Frequently asked questions

npx skillmds@latest add 26zl/detecting-t1055-process-injection-with-sysmon