Clankerusecase
MITRE ATT&CK detection coverage
← Back to main site
Home/ MITRE Matrix/ Defense Evasion/ T1055

T1055Process Injection

T1055 — Process Injection is a MITRE ATT&CK technique in the Defense Evasion tactic. Clankerusecase tracks 40 detection use cases covering it and 5 threat-intel articles citing it.

Defense EvasionPrivilege Escalation
View on the matrix → Filter Detection Library MITRE official spec ↗
40Use cases
5Articles
12Sub-techniques
2Tactics

Sub-techniques (12)

Use cases covering this technique (40)

AWS Bedrock Claude excessive use of tokens ESCU actions · hunting P AWS Bedrock Claude High Risk Filesystem and Exec Tool Invocation ESCU actions · hunting P AWS Bedrock Claude Hostile Prompt Sentiment ESCU actions · hunting P AWS Bedrock Claude Possible Prompt Injection ESCU actions · hunting P AWS Bedrock Claude Sensitive Data in Prompts ESCU actions · hunting P AWS Bedrock Claude Unusually Large Prompts ESCU actions · hunting P Rundll32 CreateRemoteThread In Browser ESCU actions · alerting P Cisco NVM - Non-Network Binary Making Network Connection ESCU actions · hunting P Cisco NVM - Suspicious Network Connection From Process With No Args ESCU actions · hunting P Create Remote Thread In Shell Application ESCU actions · alerting P DLLHost with no Command Line Arguments with Network ESCU actions · alerting P GPUpdate with no Command Line Arguments with Network ESCU actions · alerting P Notepad with no Command Line Arguments ESCU actions · alerting P Powershell Fileless Process Injection via GetProcAddress ESCU actions · alerting P Powershell Remote Thread To Known Windows Process ESCU actions · alerting P Rundll32 Create Remote Thread To A Process ESCU actions · alerting P SearchProtocolHost with no Command Line with Network ESCU actions · alerting P Suspicious DLLHost no Command Line Arguments ESCU actions · alerting P Suspicious GPUpdate no Command Line Arguments ESCU actions · alerting P Suspicious SearchProtocolHost no Command Line Arguments ESCU actions · alerting P Trickbot Named Pipe ESCU actions · alerting P Windows List ENV Variables Via SET Command From Uncommon Parent ESCU actions · hunting P Windows Process Injection In Non-Service SearchIndexer ESCU actions · alerting P Windows Process Injection Wermgr Child Process ESCU actions · hunting P Windows Process With NamedPipe CommandLine ESCU actions · hunting P Windows PUA Named Pipe ESCU actions · hunting P Windows Remote Assistance Spawning Process ESCU actions · alerting P Windows RMM Named Pipe ESCU actions · hunting P Windows Suspicious C2 Named Pipe ESCU actions · alerting P Windows Suspicious Named Pipe ESCU actions · alerting P Winhlp32 Spawning a Process ESCU actions · alerting P Wscript Or Cscript Suspicious Child Process ESCU actions · hunting P Cisco Secure Firewall - Communication Over Suspicious Ports ESCU actions · hunting P Cobalt Strike Named Pipes ESCU actions · alerting P Splunk Process Injection Forwarder Bundle Downloads ESCU actions · hunting P Windows Command Shell Fetch Env Variables ESCU actions · alerting P [LLM] pythonw.exe loader executing from deceptive %LocalAppData%\Temp dir (ACR Stealer) Bespoke install · hunting DSΣPDDCS [LLM] BusySnake NSIS dropper: pnx.exe injected from Temp\ns*.tmp staging folder Bespoke install · alerting DSΣPDDCS [LLM] SPECTRALVIPER injected OneDrive.Sync.Service.exe beaconing (Cookie-header C2) Bespoke c2 · alerting DSPDDCS [LLM] EDR-Freeze: WerFaultSecure.exe abused to suspend AV/EDR processes via MiniDumpWriteDump race Bespoke install · alerting DSΣP

Articles citing this technique (5)