T1055 Process Injection
Adversaries may inject code into processes in order to evade process-based defenses as well as possibly elevate privileges. Process injection is a method of executing arbitrary code in the address space of a separate live process. Running code in the context of another process may allow access to the process's memory, system/network resources, and possibly elevated privileges. Execution via…
Quién la usa · con noticias en Jábega
Reglas Sigma para cazarla
- Antivirus PrinterNightmare CVE-2021-34527 Exploit Detectioncriticalstable · antivirus
- Potential Dridex Activitycriticalstable · windows
- CobaltStrike Named Pipecriticaltest · windows
- CobaltStrike Named Pipe Pattern Regexcriticaltest · windows
- HackTool - DInjector PowerShell Cradle Executioncriticaltest · windows
- Malicious Named Pipe Createdcriticaltest · windows
- RedSun - Named Pipe Createdcriticalexperimental · windows
- RedSun - TieringEngineService.exe Detected as EICAR Test Filecriticalexperimental · windows
- APT PRIVATELOG Image Load Patternhightest · windows
- CobaltStrike Named Pipe Patternshightest · windows
- Dllhost.EXE Execution Anomalyhightest · windows
- DotNet CLR DLL Loaded By Scripting Applicationshightest · windows
- Execution Of Non-Existing Filehightest · windows
- HackTool - CACTUSTORCH Remote Thread Creationhightest · windows
- HackTool - CoercedPotato Executionhightest · windows
- HackTool - CoercedPotato Named Pipe Creationhightest · windows
- HackTool - EfsPotato Named Pipe Creationhightest · windows
- HackTool - LittleCorporal Generated Maldoc Injectionhightest · windows
- HackTool - Potential CobaltStrike Process Injectionhightest · windows
- Injected Browser Process Spawning Rundll32 - GuLoader Activityhightest · windows
- Malware Shellcode in Verclsid Target Processhightest · windows
- ManageEngine Endpoint Central Dctask64.EXE Potential Abusehightest · windows
- Mavinject Inject DLL Into Running Processhightest · windows
- Network Connection Initiated Via Notepad.EXEhightest · windows
- Potential Pikabot Hollowing Activityhightest · windows
Mostrando 25 de 48.
Reglas de SigmaHQ · Detection Rule License 1.1. Técnica de MITRE ATT&CK®.