Cross-source coverage

T1093 / ATT&CK

Process Hollowing

ATT&CK has retired this technique. Rules still tag it; the current id is T1055.012 Process Injection: Process Hollowing.

1 rule across 1 source.

Showing deprecated rules · back to the default

From MITRE ATT&CK 19.2

Process hollowing occurs when a process is created in a suspended state then its memory is unmapped and replaced with malicious code. Similar to Process Injection, execution of the malicious code is masked under a legitimate process and may evade defenses and detection analysis.

Tactics
Stealth
Platforms
Windows
Telemetry

chronicle/detection-rules

1 rule
Detection Severity Format
ursnif_trojan_detection_cmd_obfuscation Undefined YARA-L

Detection rules belong to the projects that publish them and remain under their own licenses. This site indexes and links to them; it claims no rights in them.