Suspicious child spawned via reflected process
Identifies the creation of a child via the clone process by employing the RtlCreateProcessReflection or RtlCloneUserProcess API. This behaviour represents a potential Dirty Vanity process injection.
- Plataforma: Windows
- Severidad: High
- Táctica MITRE: Evasión de defensas
- Técnicas MITRE: T1055