Detecting T1055 Process Injection With Sysmon

Detect process injection techniques (T1055) including classic DLL injection, process hollowing, and APC injection by analyzing Sysmon events for cross-process memory operations, remote thread creation, and anomalous DLL loading patterns.

theheavenlyd3mon 8e4ca74 8 files · 39.2 KB Updated 28 repo stars

File contents

theheavenlyd3mon/hermes-profiles/tree/main/profiles/cyber-blue-soc/skills/Anthropic-Cybersecurity-Skills/skills/detecting-t1055-process-injection-with-sysmon commit 8e4ca740b8

Frequently asked questions

npx skillmds add theheavenlyd3mon/detecting-t1055-process-injection-with-sysmon