Remcos RAT-like Multi-Stage Process Injection
Detects suspicious process injection attempts where common scripting/proxy execution tools (wscript.exe, cscript.exe, mshta.exe, powershell.exe, msiexec.exe) are used to inject into other processes (RegAsm.exe, InstallUtil.exe, vbc.exe, svchost.exe, explorer.exe) using CreateRemoteThread. The detection is further refined by looking for command-line indicators often associated with malicious activity, such as downloading content or executing scripts.
Microsoft Sentinel (KQL)

