Suspicious Process Injection via CharMap
Detects potential process injection attempts involving 'charmap.exe', a Windows system utility. The rule monitors for a sequence of memory management and thread creation API calls (OpenProcess, VirtualAlloc, WriteProcessMemory, and CreateRemoteThread) originating from or targeting this binary, which is often abused as a host for malicious code to bypass security controls.
Microsoft Sentinel (KQL)

