Technique T1055
Process Injection
Detection & mitigation
Monitor for unusual process injections, especially into trusted processes in OT environments. Deploy endpoint detection that inspects process memory and network connections for encrypted C2 patterns. Segment OT networks and enforce strict application whitelisting.