logo

Masquerading Windows processes like a DoubleAgent.

ID: 37d1d577-f424-5ba6-bfbf-3f3d80e43960

STIX ID: report--37d1d577-f424-5ba6-bfbf-3f3d80e43960

Feed Name: SensePost Blog

Threat Score
70/100

Date Published: 2020-04-23

Date Updated: 2026-04-29

...
...

This blog-style technical report demonstrates a weaponised proof-of-concept of the 2017 “DoubleAgent” Application Verifier technique (MITRE T1183) to persistently inject DLLs into Windows processes — including antivirus and system services — and use that code to dump LSASS memory for credential theft. The author tests the approach against modern AVs (Windows Defender, Cylance, McAfee), shows that static/dynamic detection was often bypassed, and recommends monitoring registry writes under Image File Execution Options with Sysmon as a detection/mitigation step.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.