Commit
This commit does not belong to any branch on this repository, and may belong to a fork outside of the repository.
feat(rules): New
DLL loaded via APC queue
rule
Identifies loading of a DLL with a callstack originating from the thread alertable state that led to the execution of an APC routine. This may be indicative of sleep obfuscation or process injection attempt.
- Loading branch information