Cross-source coverage

T1055.002 / ATT&CK

Process Injection: Portable Executable Injection

5 rules across 2 sources.

From MITRE ATT&CK 19.2

Adversaries may inject portable executables (PE) into processes in order to evade process-based defenses as well as possibly elevate privileges. PE injection is a method of executing arbitrary code in the address space of a separate live process.

PE injection is commonly performed by copying code (perhaps without a file on disk) into the virtual address space of the target process before invoking it via a new thread. The write can be performed with native Windows API calls such as VirtualAllocEx and WriteProcessMemory, then invoked with CreateRemoteThread or additional code (ex: shellcode). The displacement of the injected code does introduce the additional requirement for functionality to remap memory references.

Running code in the context of another process may allow access to the process's memory, system/network resources, and possibly elevated privileges. Execution via PE injection may also evade detection from security products since the execution is masked under a legitimate process.

Platforms
Windows
Telemetry
WinEventLog:Sysmon

How MITRE says to detect it DET0106

Behavioral Detection of PE Injection via Remote Memory Mapping

Windows Analytic 0297

Detects PE injection through a behavioral sequence where one process opens (OpenProcess) a handle to another, allocates remote memory (VirtualAllocEx), writes a PE header (MZ) or shellcode (WriteProcessMemory), then initiates a new thread (CreateRemoteThread or NtCreateThreadEx) in that process—executing injected code in memory without touching disk. Optional: injects a trampoline or shellcode that unpacks/reflectively maps the payload.

  • WinEventLog:Sysmon EventCode=10
  • WinEventLog:Sysmon EventCode=8
  • WinEventLog:Sysmon EventCode=1
  • WinEventLog:Sysmon EventCode=11

splunk/security_content

3 rules
Detection Severity Format
Windows Process Injection into Commonly Abused Processes Undefined SPL
Windows Process Injection into Notepad Undefined SPL
Windows Process Injection Remote Thread Undefined SPL

elastic/detection-rules

2 rules
Detection Severity Format
Potential Process Injection via PowerShell High Elastic TOML
Suspicious .NET Reflection via PowerShell Medium Elastic TOML

Detection rules belong to the projects that publish them and remain under their own licenses. This site indexes and links to them; it claims no rights in them.