// MITRE ATT&CK
T1055 · Process Injection
Adversaries may inject code into processes in order to evade process-based defenses as well as possibly elevate privileges. Process injection is a method of executing arbitrary code in the address space of a separate live process. Running code in the context of another process may allow access to th...
How to detect & mitigate it
Detecting Process Injection starts with your SIEM/EDR telemetry. Write a detection rule with the Sigma generator, analyze suspicious logs in the log analyzer, and place the technique on your coverage with the ATT&CK matrix.
Sub-techniques (12)
T1055.001
Dynamic-link Library Injection T1055.002
Portable Executable Injection T1055.003
Thread Execution Hijacking T1055.004
Asynchronous Procedure Call T1055.005
Thread Local Storage T1055.008
Ptrace System Calls T1055.009
Proc Memory T1055.011
Extra Window Memory Injection T1055.012
Process Hollowing T1055.013
Process Doppelgänging T1055.014
VDSO Hijacking T1055.015
ListPlanting
Dynamic-link Library Injection T1055.002
Portable Executable Injection T1055.003
Thread Execution Hijacking T1055.004
Asynchronous Procedure Call T1055.005
Thread Local Storage T1055.008
Ptrace System Calls T1055.009
Proc Memory T1055.011
Extra Window Memory Injection T1055.012
Process Hollowing T1055.013
Process Doppelgänging T1055.014
VDSO Hijacking T1055.015
ListPlanting
Related techniques
T1055.011
Extra Window Memory Injection T1205.002
Socket Filters T1027.011
Fileless Storage T1218.011
Rundll32 T1027.009
Embedded Payloads T1564.012
File/Path Exclusions T1216.001
PubPrn T1574.007
Path Interception by PATH Environment Variable
Extra Window Memory Injection T1205.002
Socket Filters T1027.011
Fileless Storage T1218.011
Rundll32 T1027.009
Embedded Payloads T1564.012
File/Path Exclusions T1216.001
PubPrn T1574.007
Path Interception by PATH Environment Variable
Source: MITRE ATT&CK®. ATT&CK is a registered trademark of The MITRE Corporation. Content for educational purposes.