detecting-t1055-process-injection-with-sysmon

mukul975/detecting-t1055-process-injection-with-sysmon · Agent Skill (multi-file)

by mukul975 · bundle

Published · Last updated


Detect process injection techniques (T1055) including classic DLL injection, process hollowing, and APC injection by analyzing Sysmon events for cross-process memory operations, remote thread creation, and anomalous DLL loading patterns.

SKILL.md

Files

This skill is a package of 8 files. Install with the command above, or download the folder.

Related

  1. hunting-for-process-injection-techniques · mukul975 bundle
    Detect process injection techniques (T1055) including CreateRemoteThread, process hollowing, and DLL injection via Sysmon Event IDs 8 and 10 and EDR process telemetry.
    24.6k
    repo stars
  2. detecting-process-hollowing-technique · mukul975 bundle
    Detect process hollowing (T1055.012) by analyzing memory-mapped sections, hollowed process indicators, and parent-child process anomalies in EDR telemetry.
    24.6k
    repo stars
  3. detecting-process-injection-techniques · mukul975 bundle
    Detects and analyzes process injection techniques used by malware, including classic DLL injection, process hollowing, APC injection, thread hijacking, and reflective loading, using memory forensics, API monitoring, and behavioral analysis.
    24.6k
    repo stars
  4. detecting-fileless-attacks-on-endpoints · mukul975 bundle
    Detects fileless malware and in-memory attacks that execute entirely in RAM without writing persistent files to disk, evading traditional antivirus. Provides detection rules for PowerShell-based attacks, reflective DLL injection, WMI persistence, and registry-resident malware.
    24.6k
    repo stars
  5. detecting-pass-the-hash-attacks · mukul975 bundle
    Hunt for Pass-the-Hash attacks by analyzing NTLM authentication patterns, identifying Type 3 logons where Kerberos is expected, and correlating with credential dumping indicators.
    24.6k
    repo stars
  6. detecting-mimikatz-execution-patterns · mukul975 bundle
    Hunt for Mimikatz execution using command-line patterns, LSASS access signatures, binary indicators, and in-memory detection of known modules.
    24.6k
    repo stars

Frequently asked questions

How do I install the detecting-t1055-process-injection-with-sysmon skill?

Run npx skillmds add mukul975/detecting-t1055-process-injection-with-sysmon in your terminal (requires Node.js), paste this page's agent-chat prompt into Claude, Cursor, or any MCP-connected agent, or download the SKILL.md file and copy it into your agent's skills directory.

What does the detecting-t1055-process-injection-with-sysmon skill do?

Detect process injection techniques (T1055) including classic DLL injection, process hollowing, and APC injection by analyzing Sysmon events for cross-process memory operations, remote thread creation, and anomalous DLL loading patterns. It is listed under Security, Coding & Dev Tools, Vulnerability Scanning on SkillMD.

Is detecting-t1055-process-injection-with-sysmon safe to use?

SkillMD's automated safety review verdict for this skill is PASS. Independent scanners report: SkillSpector: PASS, Skill Scanner: PASS. Capability flags: executes scripts. SkillMD never runs a skill's scripts for you; review the SKILL.md before installing.

Which AI agents work with detecting-t1055-process-injection-with-sysmon?

This skill is tagged as working with Claude Code, Claude.ai, OpenAI Codex. SKILL.md is an open format, so most agents that read a skills directory can load it too.

Is detecting-t1055-process-injection-with-sysmon free to use?

Yes. Installing skills from SkillMD is free. This skill is licensed under Apache-2.

Who published detecting-t1055-process-injection-with-sysmon?

mukul975 (@mukul975) published this skill. Their other Agent Skills are listed on their SkillMD profile.