Process Parameter Poisoning
ID: 59be99bf-2e6d-5f2a-bae2-f49689279af7
STIX ID: report--59be99bf-2e6d-5f2a-bae2-f49689279af7
Feed Name: SensePost Blog
This report introduces Process Parameter Poisoning (P3), a technique that injects and executes shellcode by placing payloads into process creation parameters (CommandLine, Environment, and ShellInfo) and redirecting the new process's main thread via SetThreadContext, thereby avoiding typical EDR-detected APIs such as WriteProcessMemory and VirtualAllocEx; the paper includes a public PoC implementation, a null-byte-avoiding shellcode generator, execution methods, and suggested detection indicators.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
