Pool Party process injection goes undetected by leading EDR tools
ID: 1fdf5ba9-9233-5831-a7a5-78130a75bff0
STIX ID: report--1fdf5ba9-9233-5831-a7a5-78130a75bff0
Feed Name: ThreatLocker Blog
Threat Score
**Pool Party Exploit**: A Windows process-injection technique that abuses thread pools to inject malicious code into an existing process, enabling full remote control; the authors claim it evades multiple leading EDR solutions and affects all Windows versions. Recommended actions include monitoring EDR vendor updates and using application allowlisting to block execution.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
