T1055.003 Process Injection via Cross-Process Memory Operations into High-Value Targets
Detects unauthorized cross-process memory operations targeting high-value Windows processes (e.g., lsass.exe, svchost.exe) by unsigned or untrusted processes. It also detects indicators of reflective DLL injection within process command lines.
SentinelOne

