Kryptovaluta-ticker:
sysadmin fra Cyber Security News

New Windows Process Injection Attack Evades EDR Monitoring Without WriteProcessMemory

Guru Baran
9 hours ago
10 Visninger
0 Kommentarer
New Windows Process Injection Attack Evades EDR Monitoring Without WriteProcessMemory

A Windows process injection method disclosed by security researcher Two Seven One Three sidesteps two APIs closely associated with remote code injection: VirtualAllocEx and WriteProcessMemory. Dubbed console named-pipe injection, the technique delivers payload bytes through a child console process’s redirected standard input and repurposes memory Windows has already populated. It can disrupt detections built around the familiar allocate-write-execute sequence. Process injection executes arbitrary code inside another process, potentially masking activity behind a legitimate application. MITRE ATT&CK tracks the behavior as T1055, while conventional implementations commonly open or create a target, allocate remote memory, copy...

Læs hele artiklen hos kilden.

Deltag i diskussionen — kommenter, stem og del links.

Registrer
Var dette nyttigt?
Del:

Kommentarer (0)

Log venligst ind eller opret dig for at deltage i diskussionen

Ingen kommentarer ennå. Bli den første til å kommentere!