Skip to content
← LibraryTechnique entry
INJ-PROCESS-HOLLOWINGDefense Evasion

Process Hollowing (T1055.012)

Spawn a benign process suspended, unmap its image, write attacker PE in place, resume — classic SDV stealth primitive.

§ Where this technique fits

INJ-PROCESS-HOLLOWING is catalogued under the Defense Evasion tactic of the offensive-security kill-chain. It appears in 2 approved dossiers in the registry, typically at step 3 on average.

§ Dossiers chaining this technique

§ What commonly comes next

  1. 01seen 1×
  2. 02
    Thread Execution Hijack
    INJ-THREAD-HIJACK · Defense Evasion
    seen 1×