Cross-source coverage
T1093 / ATT&CK
Process Hollowing
ATT&CK has retired this technique. Rules still tag it; the current id is T1055.012 Process Injection: Process Hollowing.
0 rules across 0 sources.
1 deprecated hidden · include
From MITRE ATT&CK 19.2
Process hollowing occurs when a process is created in a suspended state then its memory is unmapped and replaced with malicious code. Similar to Process Injection, execution of the malicious code is masked under a legitimate process and may evade defenses and detection analysis.
- Tactics
- Stealth
- Platforms
- Windows
- Telemetry
- —
No live rules cover this technique. 1 deprecated rule is hidden.