Proc Injctn Tchnqs

Detect process injection techniques (T1055) including CreateRemoteThread, process hollowing, and DLL injection via Sysmon Event IDs 8 and 10 and EDR process telemetry

undermybelt Updated

File contents

undermybelt/hermes-skills/tree/main/skills/red-teaming/anthropic-cybersecurity-skills/skills/proc-injctn-tchnqs commit 0cd833b994

Frequently asked questions

npx skillmds@latest add undermybelt/proc-injctn-tchnqs