Cross-source coverage
T1055.002 / ATT&CK
Process Injection: Portable Executable Injection
5 rules across 2 sources.
From MITRE ATT&CK 19.2
Adversaries may inject portable executables (PE) into processes in order to evade process-based defenses as well as possibly elevate privileges. PE injection is a method of executing arbitrary code in the address space of a separate live process.
PE injection is commonly performed by copying code (perhaps without a file on disk) into the virtual address space of the target process before invoking it via a new thread. The write can be performed with native Windows API calls such as VirtualAllocEx and WriteProcessMemory, then invoked with CreateRemoteThread or additional code (ex: shellcode). The displacement of the injected code does introduce the additional requirement for functionality to remap memory references.
Running code in the context of another process may allow access to the process's memory, system/network resources, and possibly elevated privileges. Execution via PE injection may also evade detection from security products since the execution is masked under a legitimate process.
- Tactics
- Stealth · Privilege Escalation
- Platforms
- Windows
- Telemetry
-
WinEventLog:Sysmon
How MITRE says to detect it DET0106
Behavioral Detection of PE Injection via Remote Memory Mapping
Windows Analytic 0297
Detects PE injection through a behavioral sequence where one process opens (OpenProcess) a handle to another, allocates remote memory (VirtualAllocEx), writes a PE header (MZ) or shellcode (WriteProcessMemory), then initiates a new thread (CreateRemoteThread or NtCreateThreadEx) in that process—executing injected code in memory without touching disk. Optional: injects a trampoline or shellcode that unpacks/reflectively maps the payload.
WinEventLog:SysmonEventCode=10WinEventLog:SysmonEventCode=8WinEventLog:SysmonEventCode=1WinEventLog:SysmonEventCode=11
splunk/security_content
3 rules| Detection | Severity | Format |
|---|---|---|
| Windows Process Injection into Commonly Abused Processes | Undefined | SPL |
| Windows Process Injection into Notepad | Undefined | SPL |
| Windows Process Injection Remote Thread | Undefined | SPL |
elastic/detection-rules
2 rules| Detection | Severity | Format |
|---|---|---|
| Potential Process Injection via PowerShell | High | Elastic TOML |
| Suspicious .NET Reflection via PowerShell | Medium | Elastic TOML |