logo

Malicious Process Environment Block Manipulation, (Fri, Jan 9th)

ID: c2114780-2047-5787-ab6c-3a67e4087c10

STIX ID: report--c2114780-2047-5787-ab6c-3a67e4087c10

Feed Name: SANS ISC Diary

Threat Score
50/100

Date Published: 2026-01-09

Date Updated: 2026-04-19

...
...

This diary-style technical write-up demonstrates how an attacker or malware can locate and modify a Windows process's PEB to overwrite the CommandLine buffer and hide or spoof process parameters; it provides proof-of-concept C code for both suspended-process modification and updating a running process, and discusses practical limitations (must not exceed original buffer length and EDRs may log original parameters at process creation).

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.