Suspicious child spawned via reflected process
Identifies the creation of a child via the clone process by employing the RtlCreateProcessReflection or RtlCloneUserProcess API. This behaviour represents a potential Dirty Vanity process injection.
- Platform: Windows
- Severity: High
- MITRE Tactic: Defense Evasion
- MITRE Techniques: T1055