Suspicious remote thread/memory write into vssvc.exe process (Spark RAT)
This rule detects potentially malicious process injection activities (CreateRemoteThreadApiCall, ProcessInjection, OpenProcessApiCall) targeting the Volume Shadow Copy Service process (vssvc.exe). It monitors for interactions originating from processes other than legitimate system processes (svchost.exe, services.exe) or vssadmin.exe, which is commonly associated with Volume Shadow Copy manipulation. Such activity often indicates attempts by malware or attackers to inject code into a critical system process to gain persistence, escalate privileges, or evade detection.
Microsoft Sentinel (KQL)

