How to hunt for anomalies in a Windows Memory Dump
Practical Example, Detect Classic Remote Process Injection