Operation DragonReturn: Non-System Process Injecting into svchost.exe
Detects cross-process injection attempts into the Windows system process 'svchost.exe' where the source process is either unsigned or lacks a verified Microsoft publisher. This pattern is commonly observed in malware payloads, such as DcRAT, attempting to hide malicious activity within a legitimate system process.
SentinelOne

