Suspicious Process Injection Targeting AI Agent Orchestrator Process
Detects attempts to inject code into an AI agent orchestrator process by monitoring for suspicious CreateRemoteThread events. This rule is designed to identify potential process hijacking attacks by malicious actors seeking to bypass application-layer controls, while excluding common legitimate security monitoring tools that may exhibit similar behavior.
Sigma

