detecting-t1055-process-injection-with-sysmon
Detect process injection techniques (T1055) including classic DLL injection, process hollowing, and APC injection by analyzing Sysmon events for cross-process memory operations, remote thread creation, and anomalous DLL loading patterns.
Source facts
- Repository
- AgentFlocks/flocks
- Last source activity
- May 5, 2026 at 05:45
- Detected SKILL.md language
- English
- Stars
- 445
- Forks
- 83
Install options
The review-first prompt is selected by default. You can switch to a direct command or download a local copy.
Review the source files
Read SKILL.md and any companion files shown by SkillsMP before deciding whether to install.