detecting-t1055-process-injection-with-sysmon
Pass
Audited by Gen Agent Trust Hub on Jun 20, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill provides legitimate cybersecurity threat hunting guidance and queries for well-known platforms like Splunk and Azure Sentinel (KQL).
- [SAFE]: No malicious code, obfuscation, or unauthorized data access patterns were detected.
- [SAFE]: Mentions of external tools such as Process Hacker and Volatility refer to standard industry software used for legitimate security analysis.
- [SAFE]: The workflow and key concepts align with established security best practices for monitoring process integrity and cross-process operations.
Audit Metadata