t1055-proc-injctn-sysmon
Detect process injection techniques (T1055) including classic DLL injection, process hollowing, and APC injection by analyzing Sysmon events for cross-process memory operations, remote thread creation, and anomalous DLL loading patterns.
Source facts
- Repository
- Undermybelt/hermes-skills
- Last source activity
- June 7, 2026 at 07:23
- Detected SKILL.md language
- English
- Stars
- 6
- Forks
- 1
Install options
The review-first prompt is selected by default. You can switch to a direct command or download a local copy.
Review the source files
Read SKILL.md and any companion files shown by SkillsMP before deciding whether to install.