logo

The Nightmare of Proc Hollow’s Exe

ID: faab3186-68d0-5f64-a53b-0fa07e99601a

STIX ID: report--faab3186-68d0-5f64-a53b-0fa07e99601a

Feed Name: TrustedSec blog

Threat Score
65/100

Date Published: 2025-03-19

Date Updated: 2026-05-01

...
...

**Executive Summary:** This technical report describes the Process Hollowing technique—how attackers create a suspended benign process, overwrite its entry point with malicious shellcode (demonstrated using Meterpreter), resume execution to gain stealthy persistence, and optionally combine it with PPID spoofing; it includes C/C# proof-of-concept code, detection ideas (API monitoring, PEB/VAD comparisons), example Sigma rules and a Splunk query, and guidance for defenders to detect and investigate such injections.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.