Important Detection 2026: Process Hollowing and Injection (T1055.012)
Detects suspicious cross-process access patterns targeting trusted system processes (svchost.exe, explorer.exe, notepad.exe) by utilizing broad process access rights (such as PROCESS_VM_WRITE and PROCESS_CREATE_THREAD). This behavior is characteristic of process injection techniques like process hollowing, often employed by loaders and malware to execute code within the context of a legitimate process.
Sigma

