Hunting For Process Injection Techniques

Detect process injection techniques (T1055) including CreateRemoteThread, process hollowing, and DLL injection via Sysmon Event IDs 8 and 10 and EDR process telemetry

theheavenlyd3mon 30c2ec3 4 files · 25.0 KB Updated 28 repo stars

File contents

theheavenlyd3mon/hermes-profiles/tree/main/profiles/cyber-blue-soc/skills/Anthropic-Cybersecurity-Skills/skills/hunting-for-process-injection-techniques commit 30c2ec3a4e

Frequently asked questions

npx skillmds add theheavenlyd3mon/hunting-for-process-injection-techniques