Cross-source coverage
T1093 / ATT&CK
Process Hollowing
ATT&CK has retired this technique. Rules still tag it; the current id is T1055.012 Process Injection: Process Hollowing.
1 rule across 1 source.
Showing deprecated rules · back to the default
From MITRE ATT&CK 19.2
Process hollowing occurs when a process is created in a suspended state then its memory is unmapped and replaced with malicious code. Similar to Process Injection, execution of the malicious code is masked under a legitimate process and may evade defenses and detection analysis.
- Tactics
- Stealth
- Platforms
- Windows
- Telemetry
- —
chronicle/detection-rules
1 rule| Detection | Severity | Format |
|---|---|---|
| ursnif_trojan_detection_cmd_obfuscation | Undefined | YARA-L |