Remote thread injection into Chrome broker process (BlueMoon pp stage)
Detects suspicious process injection attempts originating from or targeting the Google Chrome browser (chrome.exe). The rule identifies cross-process activities such as remote thread creation or opening processes with high-privilege access masks (0x1FFFFF), which are common techniques used by malware to execute code within the memory space of a legitimate web browser.
Microsoft Sentinel (KQL)

