logo

Pool Party process injection goes undetected by leading EDR tools

ID: 1fdf5ba9-9233-5831-a7a5-78130a75bff0

STIX ID: report--1fdf5ba9-9233-5831-a7a5-78130a75bff0

Feed Name: ThreatLocker Blog

Threat Score
75/100

Date Published: 2025-01-03

Date Updated: 2026-05-01

...
...

**Pool Party Exploit**: A Windows process-injection technique that abuses thread pools to inject malicious code into an existing process, enabling full remote control; the authors claim it evades multiple leading EDR solutions and affects all Windows versions. Recommended actions include monitoring EDR vendor updates and using application allowlisting to block execution.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.