Clankerusecase
MITRE ATT&CK detection coverage
← Back to main site
Home/ MITRE Matrix/ Defense Evasion/ T1055.012

T1055.012Process Hollowing

T1055.012 — Process Hollowing is a MITRE ATT&CK technique in the Defense Evasion tactic. Clankerusecase tracks 2 detection use cases covering it and 1 threat-intel article citing it.

Defense EvasionPrivilege Escalation
View on the matrix → Filter Detection Library MITRE official spec ↗
2Use cases
1Articles
0Sub-techniques
2Tactics

Use cases covering this technique (2)

PowerShell PInvoke Process Injection API Chain ESCU actions · alerting P [LLM] whisper.dll loaded / svchost.exe spawned outside services.exe (GopherWhisper JabGopher injection) Bespoke install · alerting DSΣPDDCS

Articles citing this technique (1)