Remote Thread Process Injection via Cross Process Event (T1055.001)
This rule detects cross-process operations (such as memory access or thread injection) initiated by processes that are not signed by known, trusted vendors, or that do not reside in protected system directories. This behavior is a common indicator of process injection techniques used to evade security controls.
SentinelOne

