PowerShell process injection via direct syscalls into csc/chrome/msedge/SearchIn
Detects instances where PowerShell attempts to inject code into legitimate processes (such as csc.exe, chrome.exe, msedge.exe, or SearchIndexer.exe) using direct syscalls NtAllocateVirtualMemoryRemote or NtSetContextThreadRemote, indicating potential process injection activity.
Splunk (SPL)

