Instrument
VisorHollow
Process-injection detection benchmark with Sysmon validation
§ Workflow phase
- 01 hunt
- 02 analyze
- 03 enrich
- 04 report
- 05 instrument
Instrumentation. The lab's own infrastructure.
VisorHollow is a process-injection detection benchmark, NtMapViewOfSection
WriteProcessMemorychains tested against Sysmon configurations with pass / fail per Event ID.
Used to validate whether an org’s Sysmon ruleset actually catches the injection chains it claims to.
§ instrument layer