Potential Process Injection Via Msra.EXE — Detection Rule

Detects potential process injection via Microsoft Remote Asssistance (Msra.exe) by looking at suspicious child processes spawned from the aforementioned process. It has been a target used by many threat actors and used for discovery and persistence tactics

Read the full analysis on IntelFusions