Sysmon 13, released by Microsoft has a new security feature that detects whether a process has been affected by malware.

One of the techniques hackers use is to inject malicious code into a legitimate Windows process to avoid detection. This tactic allows the malware to run, but Task Manager detects it as a standard Windows process running in the background.
Hollowing technique starts with a legitimate process in a suspended state, which then replaces the legitimate code with malicious code . This malicious code is then executed by the process, with whatever privileges are granted to the process.
Herpaderping is a more advanced technique where malware modifies its disk image to look like legitimate software after the malware is loaded. When security software scans the file on disk, it will see a harmless file while the malicious code is executing in memory .
Many well-known malware use similar techniques to evade detection, including Mailto/defray777 ransomware, TrickBot , and BazarBackdoor.

If you're not familiar with Sysmon or System Monitor, it's a tool from Sysinternals designed to monitor systems for malicious activity and record those events in the Windows event log.
You can download Sysmon from the Sysinternals page or https://live.sysinternals.com/sysmon.exe.
To enable tamper detection, administrators must add the "ProcessTampering" configuration option to a configuration file. Sysmon will simply monitor basic events such as process creation and file time changes without a configuration file.
This new directive has been added to Sysmon 4.50, which can be viewed by running the sysmon -s command.
Once launched, the program will install the driver and begin collecting data silently in the background.
All Sysmon events will be logged in "Applications and Services Logs/Microsoft/Windows/Sysmon/Operational" in Event Viewer.
With the ProcessTampering feature enabled, when a Hollowing process or herpaderping process is detected, Sysmon will create an “Event 25 – Process Tampering” entry in the Event Viewer.
To learn more about Sysmon, visit the Sysinternals and try out the various configuration options it offers.
