Detecting T1055 Process Injection With Sysmon

Detect process injection techniques (T1055) including classic DLL injection, process hollowing, and APC injection by analyzing Sysmon events for cross-process memory operations, remote thread creation, and anomalous DLL loading patterns.

xalgord 1fed994 8.2 KB Updated

File contents

xalgord/xalgorix/tree/main/internal/tools/skills/data/threat-hunting/detecting-t1055-process-injection-with-sysmon commit 1fed99413b

Frequently asked questions

npx skillmds@latest add xalgord/detecting-t1055-process-injection-with-sysmon