// REFERENCE

Sysmon 8 — CreateRemoteThread

Log: Sysmon/Operational High risk

A process created a thread in another process (Sysmon). It's a direct signature of code injection: the source writes and runs code in the target. Rare when legitimate; a high-priority hunt.

Related tools

Work with this in:

Related

Original descriptions based on Microsoft's public documentation. IDs and fields may vary with the Windows version and the active audit policy.