Remote Thread Injection into Sensitive System Processes via CreateRemoteThread
This rule detects suspicious remote thread creation events (Sysmon Event ID 8) where a process initiates a thread in high-value system processes like lsass.exe, svchost.exe, explorer.exe, or winlogon.exe. It specifically filters out activity originating from common Windows system directories, highlighting potential process injection attempts by unauthorized binaries.
Splunk (SPL)

