logo

Get-InjectedThreadEx – Detecting Thread Creation Trampolines

ID: 6f7e8239-73bd-52d4-a305-ac0f34d30721

STIX ID: report--6f7e8239-73bd-52d4-a305-ac0f34d30721

Feed Name: Elastic Security Labs

Threat Score
55/100

Date Published: 2022-12-07

Date Updated: 2026-04-27

...
...

This report analyzes how memory-resident malware can evade thread-creation detections by using four trampoline classes—inline hooks, thread-context hijacks/APC (illusionary trampolines), in-image gadgets, and legitimate library functions repurposed as trampolines—and presents detection strategies and an updated PowerShell tool (Get-InjectedThreadEx) that inspects thread start addresses, CFG bitmap state, working set sharing, call-stack anomalies, and byte-pattern heuristics to hunt for suspicious thread creations.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.