• CommunityEnterprisePlans
  • Intel Exchange
    Intel ExchangeDetections
  • Resources
  • About
  • Leaderboard
Join CommunitySign In
    All Detections

    SloppyRAT Hell's Gate Indirect Syscall Process Injection

    avatar
    GlassDiceBearhttps://www.dicebear.comhttps://creativecommons.org/publicdomain/zero/1.0/„Glass” (https://www.dicebear.com) by „DiceBear”, licensed under „CC0 1.0” (https://creativecommons.org/publicdomain/zero/1.0/)
    Ibrahim Saud@tektrix
    •updated 20 days ago•0•0•0

    Detects process injection behavior by monitoring for the usage of specific Windows API functions (NtAllocateVirtualMemory, NtCreateThreadEx, NtProtectVirtualMemory, NtWriteVirtualMemory, NtOpenProcess) frequently used by adversaries to execute malicious code within the context of a legitimate process.

    SentinelOne

    Tags

    T1055 - Process InjectionTA0005 - StealthProcess TamperingProcess Remote Thread CreationWindowsWindows Sysmon

    Found in

    • SloppyRAT Ransomware Foothold Tool AnalysisLast updated 21 days ago
    • SloppyRAT Ransomware Foothold Tool AnalysisLast updated 21 days ago
    • SloppyRAT Ransomware Foothold Tool AnalysisLast updated 21 days ago
    • SloppyRAT Ransomware Foothold Tool AnalysisLast updated 21 days ago
    • SloppyRAT Ransomware Foothold Tool AnalysisLast updated 21 days ago

    Community Inspired.
    AI Enhanced.
    Better Detections.

    Follow Us

    Company

    • About
    • Leaderboard

    Product

    • Community
    • Enterprise
    • Plans

    © 2026 Copyright. All Rights Reserved.

    Privacy PolicyTerms of Service

    Sign up to view this detection

    or

    Already have an account?