BigHugger
sk Skill · mukul975

detecting-t1055-process-injection-with-sysmon

Detect process injection techniques (T1055) — including DLL injection, process hollowing, and APC injection — by analyzing Sysmon Event IDs 1, 7, 8, 10, and 25 for cross-process memory operations, remote thread creation, and anomalous DLL loads. Use when hunting defense-evasion activity that hides code inside legitimate processes, investigating an EDR alert on suspicious cross-process access, or validating Sysmon…

installs 8w
0
30-day movement
starts with the next reading
Related entries
1
Connections
0
kqlPythonprocess-hollowingdefense-evasionmitre-t1055sysmondll-injectionprocess-injectionyamlsplthreat-hunting
Host repository
mukul975/Anthropic-Cybersecurity-Skills
Version
1.0
Licence
Apache-2.0
Host stars
33k
Host language
Python