Hunting For Process Injection Techniques

Detect process injection techniques (T1055) including CreateRemoteThread, process hollowing, and DLL injection via Sysmon Event IDs 8 and 10 and EDR process telemetry

xalgord acfcbf2 3.3 KB Updated

File contents

xalgord/xalgorix/tree/main/internal/tools/skills/data/threat-hunting/hunting-for-process-injection-techniques commit acfcbf241b

Frequently asked questions

npx skillmds@latest add xalgord/hunting-for-process-injection-techniques