BigHugger
sk Skill · mukul975

detecting-process-hollowing-technique

Detect process hollowing (MITRE T1055.012) by analyzing memory-mapped sections, hollowed process indicators, and parent-child anomalies using EDR telemetry, Volatility's malfind plugin, pe-sieve, Hollows Hunter, and Sysmon Event ID 25. Use when investigating a legitimate-looking process (svchost.exe, explorer.exe, rundll32.exe) suspected of hosting injected code via NtUnmapViewOfSection.

installs 8w
0
30-day movement
starts with the next reading
Related entries
1
Connections
0
Pythonproactive-detectiont1055edrprocess-injectionprocess-hollowingmitre-attackthreat-hunting
Host repository
mukul975/Anthropic-Cybersecurity-Skills
Version
1.0
Licence
Apache-2.0
Host stars
33k
Host language
Python