Get-InjectedThreadEx – Detecting Thread Creation Trampolines
ID: 6f7e8239-73bd-52d4-a305-ac0f34d30721
STIX ID: report--6f7e8239-73bd-52d4-a305-ac0f34d30721
Feed Name: Elastic Security Labs
This report analyzes how memory-resident malware can evade thread-creation detections by using four trampoline classes—inline hooks, thread-context hijacks/APC (illusionary trampolines), in-image gadgets, and legitimate library functions repurposed as trampolines—and presents detection strategies and an updated PowerShell tool (Get-InjectedThreadEx) that inspects thread start addresses, CFG bitmap state, working set sharing, call-stack anomalies, and byte-pattern heuristics to hunt for suspicious thread creations.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
