Malware Series: Process Injection Mapped Sections
ID: b6867162-7feb-58fd-ad3c-d8af751f4991
STIX ID: report--b6867162-7feb-58fd-ad3c-d8af751f4991
Feed Name: TrustedSec blog
Threat Score
This report is a technical how-to describing a Windows process-injection technique using NtCreateSection/NtMapViewOfSection to create a kernel-backed shared memory section, map views into local and remote processes, copy shellcode (msfvenom example) into the shared view, and execute it via a remote thread; C and C# code examples are provided to demonstrate the method.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
