logo

Time Travel Triage: An Introduction to Time Travel Debugging using a .NET Process Hollowing Case Study

ID: 2ee9f1ef-1f97-53fa-8fa0-0cea6a71ad62

STIX ID: report--2ee9f1ef-1f97-53fa-8fa0-0cea6a71ad62

Feed Name: Threat Intelligence

Threat Score
65/100

Date Published: 2025-11-13

Date Updated: 2026-04-27

Author: Mandiant

...
...

This report demonstrates how Microsoft WinDbg's Time Travel Debugging (TTD) can accelerate analysis of obfuscated multi-stage .NET droppers by allowing analysts to record and replay execution to rapidly locate key API calls and payload delivery events. Using a case study of a .NET dropper that performs process hollowing (with InstallUtil.exe observed as a suspicious child process), the write-up explains TTD's advantages, limitations, and how it helps bypass layers of .NET obfuscation to surface injection and shellcode-related behaviors.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.