BigHugger
sk Skill · mukul975

hunting-for-process-injection-techniques

Detects process injection techniques (MITRE T1055) — including CreateRemoteThread injection, process hollowing, and DLL injection — by analyzing Sysmon Event IDs 8 (CreateRemoteThread) and 10 (ProcessAccess) alongside EDR process telemetry. Use when hunting for in-memory code injection or defense evasion via legitimate process abuse on Windows endpoints.

installs 8w
0
30-day movement
starts with the next reading
Related entries
1
Connections
0
Pythonthreat-huntingcreateremotethreadedrsysmont1055dll-injectionprocess-injection
Host repository
mukul975/Anthropic-Cybersecurity-Skills
Version
1.0
Licence
Apache-2.0
Host stars
33k
Host language
Python