Sauron Loader Shellcode Injection into attrib.exe
Detects process injection behaviors (e.g., remote thread creation, memory allocation) targeting the attrib.exe process. Such activity is often associated with process hollowing or reflective shellcode injection, consistent with loader behavior used to execute in-memory payloads within legitimate, rarely-used system utilities.
Microsoft Sentinel (KQL)

