The Nightmare of Proc Hollow’s Exe
ID: faab3186-68d0-5f64-a53b-0fa07e99601a
STIX ID: report--faab3186-68d0-5f64-a53b-0fa07e99601a
Feed Name: TrustedSec blog
**Executive Summary:** This technical report describes the Process Hollowing technique—how attackers create a suspended benign process, overwrite its entry point with malicious shellcode (demonstrated using Meterpreter), resume execution to gain stealthy persistence, and optionally combine it with PPID spoofing; it includes C/C# proof-of-concept code, detection ideas (API monitoring, PEB/VAD comparisons), example Sigma rules and a Splunk query, and guidance for defenders to detect and investigate such injections.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
