Ransomware Series: Process Injection into Legitimate Windows Processes
This rule detects various process injection techniques (such as CreateRemoteThread, QueueUserAPC, and remote memory writes) initiated by external processes targeting high-value, commonly abused Windows system processes like svchost.exe, lsass.exe, and explorer.exe. These techniques are often used by ransomware and other malware to hide malicious code execution within trusted system memory space.
Microsoft Sentinel (KQL)

