Login
Download
Skill UI
Browse and discover
10318+
curated skills
All
Development
Artificial Intelligence
Design & Creative
Product & Business
Data Science
Marketing
Soft Skills
Productivity
Engineering
Languages
Search
Process Hollowing
, found
3
results
Default
Newest
Most Downloaded
Detecting Process Injection Using Sysmon Events
detecting-t1055-process-injection-with-sysmon
mukul975/Anthropic-Cybersecurity-Skills
453
This guide details how to detect advanced process injection techniques (T1055) by analyzing rich Sysmon telemetry. It focuses on identifying cross-process memory operations, such as remote thread creation (Event 8), suspicious process access (Event 10), and memory divergence (ProcessTampering/Event 25), which are hallmarks of DLL injection and process hollowing. Ideal for threat hunters and security analysts investigating sophisticated defense evasion.
View Details
Extracting Memory Artifacts with Rekall
extracting-memory-artifacts-with-rekall
mukul975/Anthropic-Cybersecurity-Skills
458
This tool leverages the Rekall memory forensics framework to conduct deep analysis of memory dumps. It is designed to detect sophisticated threats such as process hollowing, injected code via VAD anomalies, hidden operating system processes, and rootkit presence. It applies key forensic plugins (pslist, malfind, vadinfo) essential for rigorous incident response and malware analysis.
View Details
Analyzing Memory Dumps with Volatility 3
performing-memory-forensics-with-volatility3
mukul975/Anthropic-Cybersecurity-Skills
126
A comprehensive guide for digital forensics professionals on analyzing volatile memory dumps using Volatility 3. Learn to extract critical evidence, including running processes, network connections, loaded DLLs, system credentials, and detecting advanced threats like process hollowing and rootkits. Essential for incident response and malware analysis.
View Details
1
Language
简体中文
English