Ransomware Series: Process Injection into Legitimate Windows Processes

This rule detects various process injection techniques (such as CreateRemoteThread, QueueUserAPC, and remote memory writes) initiated by external processes targeting high-value, commonly abused Windows system processes like svchost.exe, lsass.exe, and explorer.exe. These techniques are often used by ransomware and other malware to hide malicious code execution within trusted system memory space.