tag
process-hollowing▌
2 indexed skills · max 10 per page
skills (2)
detecting-process-hollowing-technique
mukul975/Anthropic-Cybersecurity-Skills · detecting-process-hollowing-technique
Detect process hollowing (T1055.012) by analyzing memory-mapped sections, hollowed process indicators, and parent-child process anomalies in EDR telemetry.
detecting-t1055-process-injection-with-sysmon
mukul975/Anthropic-Cybersecurity-Skills · detecting-t1055-process-injection-with-sysmon
Detect process injection techniques (T1055) including classic DLL injection, process hollowing, and APC injection by analyzing Sysmon events for cross-process memory operations, remote thread creation, and anomalous DLL loading patterns.