| name | detecting-t1055-process-injection-with-sysmon |
| description | Detect process injection techniques (T1055) including classic DLL injection, process hollowing, and APC injection by analyzing Sysmon events for cross-process memory operations, remote thread creation, and anomalous DLL loading patterns. Use when detecting process injection techniques (t1055) including classic dll injection, process. |
| domain | cybersecurity |
| tags | ["threat-hunting","process-injection","sysmon","mitre-t1055","defense-evasion","dll-injection","process-hollowing"] |
| subdomain | threat-hunting |
| version | 1.0 |
| author | oyi77 |
| license | Apache-2.0 |
| d3fend_techniques | ["Executable Denylisting","Execution Isolation","File Metadata Consistency Validation","Content Format Conversion","File Content Analysis"] |
| nist_csf | ["DE.CM-01","DE.AE-02","DE.AE-07","ID.RA-05"] |
Detecting T1055 Process Injection With Sysmon
Overview
Cybersecurity skill for detecting t1055 process injection with sysmon. Follows industry best practices and security standards.
When to Use
Trigger phrases:
-
"detecting t1055 process injection with sysmon"
-
"Detect process injection techniques (T1055) including classic DLL injection, pro"
-
When hunting for defense evasion techniques that hide malicious code inside legitimate processes
-
After EDR alerts for suspicious cross-process memory access or remote thread creation
-
When investigating malware that injects into svchost.exe, explorer.exe, or other system processes
-
During purple team exercises testing detection of process injection variants
-
When validating Sysmon configuration coverage for injection detection
When NOT to Use
- When you lack proper authorization for testing
- For production systems without change management
- When the task requires legal or compliance expertise beyond technical scope
Prerequisites
- Sysmon deployed with comprehensive configuration capturing Events 1, 7, 8, 10, 25
- Event ID 8 (CreateRemoteThread) enabled for remote thread detection
- Event ID 10 (ProcessAccess) configured with appropriate access mask filters
- Event ID 7 (ImageLoaded) for DLL injection detection
- Event ID 25 (ProcessTampering) for process hollowing on Sysmon 13+
- SIEM platform for correlation and alerting
Workflow
import re
IOC_PATTERNS = {
"ip": r"\b(?:\d{1,3}\.){3}\d{1,3}\b",
"domain": r"\b[a-z0-9-]+\.[a-z]{2,}\b",
"hash_md5": r"\b[a-f0-9]{32}\b",
"hash_sha256": r"\b[a-f0-9]{64}\b",
}
def extract_iocs(text: str) -> dict:
return {k: re.findall(v, text) k, v IOC_PATTERNS.items()}