• CommunityEnterprisePlans
  • Intel Exchange
    Intel ExchangeDetections
  • Resources
  • About
  • Leaderboard
Join CommunitySign In
    All Detections

    PowerShell process injection via direct syscalls into csc/chrome/msedge/SearchIn

    avatar
    GlassDiceBearhttps://www.dicebear.comhttps://creativecommons.org/publicdomain/zero/1.0/„Glass” (https://www.dicebear.com) by „DiceBear”, licensed under „CC0 1.0” (https://creativecommons.org/publicdomain/zero/1.0/)
    Ibrahim Saud@tektrix
    •updated 22 days ago•0•0•2

    Detects instances where PowerShell attempts to inject code into legitimate processes (such as csc.exe, chrome.exe, msedge.exe, or SearchIndexer.exe) using direct syscalls NtAllocateVirtualMemoryRemote or NtSetContextThreadRemote, indicating potential process injection activity.

    Splunk (SPL)

    Tags

    T1055 - Process InjectionT1055.002 - Portable Executable InjectionT1055.012 - Process HollowingTA0005 - StealthProcess Remote Thread CreationPowershell Script ExecutionProcess TamperingEDR AlertWindowsCrowdstrike Falcon EDRSentinelone EDRCybereason EDRCarbonblack EDRspl

    Found in

    • ClickFix Campaign Targets News Outlet with StealCLast updated 22 days ago
    • ClickFix Campaign Targets News Outlet with StealCLast updated 22 days ago
    • ClickFix Campaign Targets News Outlet with StealCLast updated 22 days ago
    • ClickFix Campaign Targets News Outlet with StealCLast updated 22 days ago
    • ClickFix Campaign Targets News Outlet with StealCLast updated 22 days ago

    Community Inspired.
    AI Enhanced.
    Better Detections.

    Follow Us

    Company

    • About
    • Leaderboard

    Product

    • Community
    • Enterprise
    • Plans

    © 2026 Copyright. All Rights Reserved.

    Privacy PolicyTerms of Service

    Sign up to view this detection

    or

    Already have an account?