Detecting T1055 Process Injection With Sysmon

Detect process injection techniques (T1055) including classic DLL injection, process hollowing, and APC injection by analyzing Sysmon events for cross-process memory operations, remote thread creation, and anomalous DLL loading patterns.

yanacuti1121 b474414 8 files · 39.2 KB Updated 2 repo stars

File contents

yanacuti1121/Yana-AI/tree/main/core/skills/detecting-t1055-process-injection-with-sysmon commit b474414353

Frequently asked questions

npx skillmds add yanacuti1121/detecting-t1055-process-injection-with-sysmon