Mavinject.exe Abused for DLL Injection into Running Process

Detects the execution of mavinject.exe with the /INJECTRUNNING command-line argument. This utility is a signed Microsoft binary that can be abused by adversaries to inject arbitrary DLLs into the address space of running processes, a technique often used to evade detection or achieve code execution.