SOP-29: Fileless Malware / Process Injection Response
SOC analyst playbook for detecting and responding to fileless malware, process injection, process hollowing, reflective DLL loading, and PPID spoofing. DeviceEvents CreateRemoteThread injection ActionTypes, DeviceProcessEvents parent-child anomalies. KQL for Sentinel, SPL for Splunk.
Rudra Verma, Senior Security Architect & Researcher