Suspicious CreateRemoteThread into trusted host process (StartAddress outside mo

Detects the creation of a remote thread (Sysmon Event ID 8) by a process into a set of common host processes (e.g., svchost.exe, explorer.exe) where the starting address of the thread does not map to a known loaded module. This behavior is highly indicative of reflective code injection or shellcode execution within the address space of a remote process.