SloppyRAT Hell's Gate Indirect Syscall Process Injection
Detects process injection behavior by monitoring for the usage of specific Windows API functions (NtAllocateVirtualMemory, NtCreateThreadEx, NtProtectVirtualMemory, NtWriteVirtualMemory, NtOpenProcess) frequently used by adversaries to execute malicious code within the context of a legitimate process.
SentinelOne

