sk Skill · mukul975
detecting-t1055-process-injection-with-sysmon
Detect process injection techniques (T1055) — including DLL injection, process hollowing, and APC injection — by analyzing Sysmon Event IDs 1, 7, 8, 10, and 25 for cross-process memory operations, remote thread creation, and anomalous DLL loads. Use when hunting defense-evasion activity that hides code inside legitimate processes, investigating an EDR alert on suspicious cross-process access, or validating Sysmon…
Open on skills.sh ↗read 2026-09-17
- installs 8w
- 0
- 30-day movement
- starts with the next reading
- Related entries
- 1
- Connections
- 0
kqlPythonprocess-hollowingdefense-evasionmitre-t1055sysmondll-injectionprocess-injectionyamlsplthreat-hunting
- Host repository
- mukul975/Anthropic-Cybersecurity-Skills
- Version
- 1.0
- Licence
- Apache-2.0
- Host stars
- 33k
- Host language
- Python