RWX memory allocation followed by Thread Pool API code execution
This rule detects potential process injection or evasion attempts by correlating the allocation of memory with Read-Write-Execute (RWX) permissions followed by the execution of Windows Thread Pool APIs (CreateThreadpoolWork, SubmitThreadpoolWork, or WaitForThreadpoolWorkCallbacks). Attackers may use these APIs as a mechanism to execute malicious code within a thread, bypassing standard monitoring of traditional thread creation APIs.
Microsoft Sentinel (KQL)

