sk Skill · meltedinhex
hunting-process-injection-with-sysmon
Hunts for process injection using Sysmon telemetry: correlating CreateRemoteThread (EID 8), suspicious cross-process access (EID 10), and RWX image-less memory to surface hollowing, shellcode injection, and APC abuse. Activates for requests to hunt process injection, analyze Sysmon EID 8/10, or detect code injection on Windows.
Open on skills.sh ↗read 2026-09-15
- installs 8w
- 0
- 30-day movement
- starts with the next reading
- Related entries
- 1
- Connections
- 0
bashPythondetectionwindowsedrsysmonprocess-injectionthreat-hunting
- Host repository
- meltedinhex/analyst-ai-pack
- Version
- 1.0.0
- Licence
- Apache-2.0
- Host stars
- 22
- Host language
- Python