https://docs.microsoft.com/en-us/sysinternals/downloads/sysmon
This update to Sysmon adds a process image tampering event that reports when the mapped image of a process doesn’t match the on-disk...
Updated Jan 11, 2021
Version 1.0lukekim
Former Employee
Joined June 18, 2019
Sysinternals Blog
Follow this blog board to get notified when there's new activity