Hunting For Process Injection Techniques

Detect process injection techniques (T1055) including CreateRemoteThread, process hollowing, and DLL injection via Sysmon Event IDs 8 and 10 and EDR process telemetry

thedixitjain a5053f7 4 files · 25.1 KB Updated 2 repo stars

File contents

thedixitjain/the-mega-skill-library/tree/main/library/general-purpose/hunting-for-process-injection-techniques commit a5053f743b

Frequently asked questions

npx skillmds add thedixitjain/hunting-for-process-injection-techniques