Skip to main content
在 Manus 中运行任何 Skill
一键导入

detecting-t1055-process-injection-with-sysmon

Detect process injection techniques (T1055) including classic DLL injection, process hollowing, and APC injection by analyzing Sysmon events for cross-process memory operations, remote thread creation, and anomalous DLL loading patterns.

星标15,069
分支1,792
更新时间2026年6月1日 10:13
文件资源管理器
8 个文件
SKILL.md
readonly