detecting-t1055-process-injection-with-sysmon
mukul975/Anthropic-Cybersecurity-Skills
This guide details how to detect T1055 process injection techniques, including DLL injection, process hollowing, and remote thread creation. By analyzing specific Sysmon Event IDs (1, 7, 8, 10, 25) that track cross-process memory operations and handle access, security teams can proactively hunt for defense-evasion activities, investigate EDR alerts, or validate security monitoring coverage.