Process injection into non-critical svchost.exe service host (Spark RAT)
This rule detects cross-process injection techniques, such as OpenProcess, CreateRemoteThread, and memory modifications, specifically targeting 'svchost.exe' instances that do not appear to be hosting critical Windows services. By filtering out known critical services (e.g., RpcSs, DcomLaunch), the rule flags suspicious attempts to inject code into legitimate service host processes to mask malicious activity.
Microsoft Sentinel (KQL)

