Best Detection of 2026 Series: Process Injection into Host Process Followed by Cloud C2 Traffic

This rule detects instances where common system processes (svchost.exe, explorer.exe, dllhost.exe) perform process injection activities, followed within a 5-minute window by a network connection to known SaaS and collaborative platforms (Slack, Discord, Dropbox, Trello). This combination is often indicative of malicious code executing within a trusted process to facilitate command and control or data exfiltration.