Mavinject.exe DLL Injection via /INJECTRUNNING
Detects the execution of Microsoft Application Virtualization Injector (mavinject.exe) with the '/injectrunning' command-line argument. This utility is frequently abused by adversaries to inject malicious DLLs into target processes, facilitating arbitrary code execution while potentially bypassing security detections due to the binary's legitimate provenance.
SentinelOne

