Cross-Process Injection: Browser/Office/Script Host Targeting System Processes
This rule detects cross-process operations where common user applications or scripting hosts initiate activity towards sensitive system processes (e.g., lsass.exe, services.exe). This pattern is a frequent indicator of process injection techniques used to achieve code execution in the context of high-privilege or critical system services, often for the purpose of credential theft or persistence.
SentinelOne

