hunting-for-process-injection-techniques

mukul975/hunting-for-process-injection-techniques · Agent Skill (multi-file)

by mukul975 · bundle

Published · Last updated


Detect process injection techniques (T1055) including CreateRemoteThread, process hollowing, and DLL injection via Sysmon Event IDs 8 and 10 and EDR process telemetry.

SKILL.md

Files

This skill is a package of 4 files. Install with the command above, or download the folder.

  • 📄SKILL.md entry
  • 📁references
  • 📄api-reference.md 2.9 KB
  • 📁scripts
  • ⚙️agent.py 8.9 KB
  • 📄LICENSE 11.0 KB

Related

  1. detecting-t1055-process-injection-with-sysmon · mukul975 bundle
    Detect process injection techniques (T1055) including classic DLL injection, process hollowing, and APC injection by analyzing Sysmon events for cross-process memory operations, remote thread creation, and anomalous DLL loading patterns.
    24.6k
    repo stars
  2. detecting-service-account-abuse · mukul975 bundle
    Detect abuse of service accounts through anomalous interactive logons, privilege escalation, lateral movement, and unauthorized access patterns.
    24.6k
    repo stars
  3. hunting-for-webshell-activity · mukul975 bundle
    Hunt for web shell deployments on internet-facing servers by analyzing file creation in web directories, suspicious process spawning from web servers, and anomalous HTTP patterns.
    24.6k
    repo stars
  4. hunting-for-unusual-network-connections · mukul975 bundle
    Hunt for unusual network connections by analyzing outbound traffic patterns, rare destinations, non-standard ports, and anomalous connection frequencies from endpoints.
    24.6k
    repo stars
  5. detecting-suspicious-powershell-execution · mukul975 bundle
    Detect suspicious PowerShell execution patterns including encoded commands, download cradles, AMSI bypass attempts, and constrained language mode evasion.
    24.6k
    repo stars
  6. hunting-for-registry-persistence-mechanisms · mukul975 bundle
    Hunt for registry-based persistence mechanisms including Run keys, Winlogon modifications, IFEO injection, and COM hijacking in Windows environments.
    24.6k
    repo stars

Frequently asked questions

How do I install the hunting-for-process-injection-techniques skill?

Run npx skillmds add mukul975/hunting-for-process-injection-techniques in your terminal (requires Node.js), paste this page's agent-chat prompt into Claude, Cursor, or any MCP-connected agent, or download the SKILL.md file and copy it into your agent's skills directory.

What does the hunting-for-process-injection-techniques skill do?

Detect process injection techniques (T1055) including CreateRemoteThread, process hollowing, and DLL injection via Sysmon Event IDs 8 and 10 and EDR process telemetry. It is listed under Security, Coding & Dev Tools, Incident Response on SkillMD.

Is hunting-for-process-injection-techniques safe to use?

SkillMD's automated safety review verdict for this skill is PASS. Independent scanners report: SkillSpector: PASS, Skill Scanner: PASS. Capability flags: executes scripts. SkillMD never runs a skill's scripts for you; review the SKILL.md before installing.

Which AI agents work with hunting-for-process-injection-techniques?

This skill is tagged as working with Claude Code, Claude.ai, OpenAI Codex. SKILL.md is an open format, so most agents that read a skills directory can load it too.

Is hunting-for-process-injection-techniques free to use?

Yes. Installing skills from SkillMD is free. This skill is licensed under Apache-2.

Who published hunting-for-process-injection-techniques?

mukul975 (@mukul975) published this skill. Their other Agent Skills are listed on their SkillMD profile.