Technique with 12 sub-techniques.View on attack.mitre.org
Adversaries may inject code into processes in order to evade process-based defenses as well as possibly elevate privileges. Process injection is a method of executing arbitrary code in the address space of a separate live process. Running code in the context of another process may allow access to the process's memory, system/network resources, and possibly elevated privileges. Execution via process injection may also evade detection from security products since the execution is masked under a legitimate process.
There are many different ways to inject code into a process, many of which abuse legitimate functionalities. These implementations exist for every major OS but are typically platform specific.
More sophisticated samples may perform multiple process injections to segment modules and further evade detection, utilizing named pipes or other inter-process communication (IPC) mechanisms as a communication channel.
Rules on DetectionCode tagged with T1055 or one of its sub-techniques.
| Rule | Type | Risk | Data source | Technique |
|---|---|---|---|---|
| AWS Bedrock Claude excessive use of tokens | Anomaly | NULL | AWS Bedrock Claude | T1055 |
| AWS Bedrock Claude High Risk Filesystem and Exec Tool Invocation | Anomaly | NULL | AWS Bedrock Claude | T1055 |
| AWS Bedrock Claude Hostile Prompt Sentiment | Anomaly | NULL | AWS Bedrock Claude | T1055 |
| AWS Bedrock Claude Possible Prompt Injection | Hunting | NULL | AWS Bedrock Claude | T1055 |
| AWS Bedrock Claude Sensitive Data in Prompts | Anomaly | NULL | AWS Bedrock Claude | T1055 |
| AWS Bedrock Claude Unusually Large Prompts | Anomaly | NULL | AWS Bedrock Claude | T1055 |
| Cisco NVM - Non-Network Binary Making Network Connection | Anomaly | NULL | Cisco Network Visibility Module Flow Data | T1055 |
| Cisco NVM - Suspicious Network Connection From Process With No Args | Anomaly | NULL | Cisco Network Visibility Module Flow Data | T1055 |
| Cisco Secure Firewall - Communication Over Suspicious Ports | Anomaly | NULL | Cisco Secure Firewall Threat Defense Connection Event | T1055 |
| Cobalt Strike Named Pipes | TTP | NULL | Sysmon EventID 17, Sysmon EventID 18 | T1055 |
| Create Remote Thread In Shell Application | TTP | NULL | Sysmon EventID 8 | T1055 |
| DLLHost with no Command Line Arguments with Network | TTP | NULL | Sysmon EventID 1 AND Sysmon EventID 3 | T1055 |
| GPUpdate with no Command Line Arguments with Network | TTP | NULL | Sysmon EventID 1 AND Sysmon EventID 3 | T1055 |
| Loading Of Dynwrapx Module | TTP | NULL | Sysmon EventID 7 | T1055.001 |
| Notepad with no Command Line Arguments | TTP | NULL | Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2 | T1055 |
| Powershell Fileless Process Injection via GetProcAddress | TTP | NULL | Powershell Script Block Logging 4104 | T1055 |
| PowerShell PInvoke Process Injection API Chain | TTP | NULL | Powershell Script Block Logging 4104 | T1055.001 T1055.003 T1055.004 T1055.012 T1055.013 |
| Powershell Remote Thread To Known Windows Process | TTP | NULL | Sysmon EventID 8 | T1055 |
| Rundll32 Create Remote Thread To A Process | TTP | NULL | Sysmon EventID 8 | T1055 |
| Rundll32 CreateRemoteThread In Browser | TTP | NULL | Sysmon EventID 8 | T1055 |
| SearchProtocolHost with no Command Line with Network | TTP | NULL | Sysmon EventID 1 AND Sysmon EventID 3 | T1055 |
| Suspicious DLLHost no Command Line Arguments | TTP | NULL | Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2 | T1055 |
| Suspicious GPUpdate no Command Line Arguments | TTP | NULL | Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2 | T1055 |
| Suspicious SearchProtocolHost no Command Line Arguments | TTP | NULL | Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2 | T1055 |
| Trickbot Named Pipe | TTP | NULL | Sysmon EventID 17, Sysmon EventID 18 | T1055 |
| Windows Command Shell Fetch Env Variables | TTP | NULL | Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2 | T1055 |
| Windows List ENV Variables Via SET Command From Uncommon Parent | Anomaly | NULL | Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2 | T1055 |
| Windows Process Injection In Non-Service SearchIndexer | TTP | NULL | Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2 | T1055 |
| Windows Process Injection into Commonly Abused Processes | Anomaly | NULL | Sysmon EventID 10 | T1055.002 |
| Windows Process Injection into Notepad | Anomaly | NULL | Sysmon EventID 10 | T1055.002 |
| Windows Process Injection Of Wermgr to Known Browser | TTP | NULL | Sysmon EventID 8 | T1055.001 |
| Windows Process Injection Remote Thread | TTP | NULL | Sysmon EventID 8 | T1055.002 |
| Windows Process Injection Wermgr Child Process | Anomaly | NULL | Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2 | T1055 |
| Windows Process Injection With Public Source Path | Hunting | NULL | Sysmon EventID 8 | T1055.002 |
| Windows Process With NamedPipe CommandLine | Anomaly | NULL | Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2 | T1055 |
| Windows PUA Named Pipe | Anomaly | NULL | Sysmon EventID 17, Sysmon EventID 18 | T1055 |
| Windows Rasautou DLL Execution | TTP | NULL | Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2 | T1055.001 |
| Windows Remote Assistance Spawning Process | TTP | NULL | Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2 | T1055 |
| Windows RMM Named Pipe | Anomaly | NULL | Sysmon EventID 17, Sysmon EventID 18 | T1055 |
| Windows Suspicious C2 Named Pipe | TTP | NULL | Sysmon EventID 17, Sysmon EventID 18 | T1055 |
| Windows Suspicious Named Pipe | TTP | NULL | Sysmon EventID 17, Sysmon EventID 18 | T1055 |
| Windows Uncommon Remote Thread Creation In Browser Process | Anomaly | NULL | Sysmon EventID 8 | T1055.001 |
| Winhlp32 Spawning a Process | TTP | NULL | Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2 | T1055 |
| Wscript Or Cscript Suspicious Child Process | Anomaly | NULL | Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2 | T1055 |
| ID | Name | Examples |
|---|---|---|
| T1055.001 | Dynamic-link Library Injection | 67 |
| T1055.002 | Portable Executable Injection | 15 |
| T1055.003 | Thread Execution Hijacking | 4 |
| T1055.004 | Asynchronous Procedure Call | 13 |
| T1055.005 | Thread Local Storage | 2 |
| T1055.008 | Ptrace System Calls | 1 |
| T1055.009 | Proc Memory | 1 |
| T1055.011 | Extra Window Memory Injection | 2 |
| T1055.012 | Process Hollowing | 43 |
| T1055.013 | Process Doppelgänging | 3 |
| T1055.014 | VDSO Hijacking | 0 |
| T1055.015 | ListPlanting | 1 |
| Used by | Procedure example |
|---|---|
| GroupAPT32 | APT32 malware has injected a Cobalt Strike beacon into Rundll32.exe. |
| GroupAPT37 | APT37 injects its malware variant, ROKRAT, into the cmd.exe process. |
| GroupAPT38 | APT38 has injected malicious payloads into the `explorer.exe` process. |
| GroupAPT41 | APT41 malware TIDYELF loaded the main WINTERLOVE component by injecting it into the iexplore.exe process. |
| GroupAPT5 | APT5 has used the CLEANPULSE utility to insert command line strings into a targeted process to alter its functionality. |
| GroupBlackByte | BlackByte has injected Cobalt Strike into `wuauclt.exe` during intrusions. BlackByte has injected ransomware into `svchost.exe` before encryption. |
| GroupCobalt Group | Cobalt Group has injected code into trusted processes. |
| GroupGamaredon Group | Gamaredon Group has injected Remcos into explorer.exe. |
| Used by | Procedure example |
|---|---|
| MalwareABK | ABK has the ability to inject shellcode into svchost.exe. |
| MalwareAgent Tesla | Agent Tesla can inject into known, vulnerable binaries on targeted hosts. |
| MalwareANDROMEDA | ANDROMEDA can inject into the `wuauclt.exe` process to perform C2 actions. |
| MalwareAttor | Attor's dispatcher can inject itself into running processes to gain higher privileges and to evade detection. |
| MalwareAuditCred | AuditCred can inject code from files to other running processes. |
| MalwareAvenger | Avenger has the ability to inject shellcode into svchost.exe. |
| MalwareBackdoor.Oldrea | Backdoor.Oldrea injects itself into explorer.exe. |
| MalwareBADHATCH | BADHATCH can inject itself into an existing explorer.exe process by using `RtlCreateUserThread`. |
| Used by | Procedure example |
|---|---|
| Campaign2015 Ukraine Electric Power Attack | During the 2015 Ukraine Electric Power Attack, Sandworm Team loaded BlackEnergy into svchost.exe, which then launched iexplore.exe for their C2. |
| Campaign3CX Supply Chain Attack | During the 3CX Supply Chain Attack, AppleJeus's VEILEDSIGNAL uses process injection to inject the C2 communication module code in the first found process instance of Chrome, Firefox, or Edge web browsers. It also monitors the established named pipe and re-injects the C2 communication module if necessary. |
| CampaignArcaneDoor | ArcaneDoor included injecting code into the AAA and Crash Dump processes on infected Cisco ASA devices. |
| CampaignCutting Edge | During Cutting Edge, threat actors used malicious SparkGateway plugins to inject shared objects into web process memory on compromised Ivanti Secure Connect VPNs to enable deployment of backdoors. |
| CampaignOperation Sharpshooter | During Operation Sharpshooter, threat actors leveraged embedded shellcode to inject a downloader into the memory of Word. |
| CampaignOperation Wocao | During Operation Wocao, threat actors injected code into a selected process, which in turn launches a command as a child process of the original. |
| CampaignRedPenguin | During RedPenguin, UNC3886 exploited CVE-2025-21590 to enable malicious code injection into the memory of legitimate processes. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.