SOP-29: Fileless Malware / Process Injection Response

SOC analyst playbook for detecting and responding to fileless malware, process injection, process hollowing, reflective DLL loading, and PPID spoofing. DeviceEvents CreateRemoteThread injection ActionTypes, DeviceProcessEvents parent-child anomalies. KQL for Sentinel, SPL for Splunk.

2026-08-15T09:48:16.332Z
Rudra Verma, Senior Security Architect & Researcher