BigHugger
sk Skill · meltedinhex

hunting-process-injection-with-sysmon

Hunts for process injection using Sysmon telemetry: correlating CreateRemoteThread (EID 8), suspicious cross-process access (EID 10), and RWX image-less memory to surface hollowing, shellcode injection, and APC abuse. Activates for requests to hunt process injection, analyze Sysmon EID 8/10, or detect code injection on Windows.

installs 8w
0
30-day movement
starts with the next reading
Related entries
1
Connections
0
bashPythondetectionwindowsedrsysmonprocess-injectionthreat-hunting
Host repository
meltedinhex/analyst-ai-pack
Version
1.0.0
Licence
Apache-2.0
Host stars
22
Host language
Python