npx claudepluginhub plurigrid/asi --plugin asiThis skill uses the workspace's default tool permissions.
Process injection (MITRE ATT&CK T1055) allows adversaries to execute code in the address space of another process, enabling defense evasion and privilege escalation. This skill detects injection techniques via Sysmon Event ID 8 (CreateRemoteThread), Event ID 10 (ProcessAccess with suspicious access rights), and analysis of source-target process relationships to distinguish legitimate from malic...
Detects process injection (T1055) via Sysmon Event IDs 8/10 including CreateRemoteThread, DLL injection; builds graphs and reports for threat hunting.
Detects process injection techniques (MITRE T1055) via Sysmon events ID 8/10 and EDR telemetry, including CreateRemoteThread, process hollowing, and DLL injection for threat hunting.
Detects T1055 process injection techniques like DLL injection, process hollowing, and APC injection via Sysmon events 1,7,8,10,25 for cross-process memory ops, remote threads, anomalous DLLs. For threat hunting.
Share bugs, ideas, or general feedback.
Process injection (MITRE ATT&CK T1055) allows adversaries to execute code in the address space of another process, enabling defense evasion and privilege escalation. This skill detects injection techniques via Sysmon Event ID 8 (CreateRemoteThread), Event ID 10 (ProcessAccess with suspicious access rights), and analysis of source-target process relationships to distinguish legitimate from malicious injection.