1 rule found
Detects when a memory process image does not match the disk image, indicative of process hollowing.