Malicious DLL Injection into Normal Processes
This rule detects attempts to inject malicious DLLs into common Windows processes such as svchost.exe, explorer.exe, lsass.exe, and winlogon.exe. The detection is based on the loading of DLLs with suspicious names like 'hook.dll', 'inject.dll', 'payload.dll', or 'stage.dll' by these processes, which is indicative of process injection techniques often used by malware like Remcos RAT.
Microsoft Sentinel (KQL)

