Skip to main content

detecting-t1055-process-injection-with-sysmon

النجوم٢٦٬٦٥٠
التفرعات٣٬٢٣٣
آخر تحديث١ يونيو ٢٠٢٦ في ١٠:١٣

Detect process injection techniques (T1055) including classic DLL injection, process hollowing, and APC injection by analyzing Sysmon events for cross-process memory operations, remote thread creation, and anomalous DLL loading patterns.

التثبيت

التثبيت باستخدام Codex أو Claude انسخ هذا Prompt والصقه في Codex أو Claude أو مساعد آخر ليراجع صفحة Skill ويثبّتها لك.

مستكشف الملفات
8 ملفات
SKILL.md
readonly