Process Injection via Remote Thread Creation (T1055)
Detects instances where one process initiates an injection mechanism (such as CreateRemoteThread, QueueUserAPC, or NtMapViewOfSection) into another process. The rule specifically alerts when these actions target common, high-value, or frequently abused processes such as explorer.exe, svchost.exe, or web browsers (chrome.exe, firefox.exe, msedge.exe), which are common targets for maintaining persistence or evading detection.
YARA-L

