Clankerusecase
MITRE ATT&CK detection coverage
← Back to main site
Home/ MITRE Matrix/ Defense Evasion/ T1055

T1055Process Injection

T1055 — Process Injection is a MITRE ATT&CK technique in the Defense Evasion tactic. Clankerusecase tracks 34 detection use cases covering it and 8 threat-intel articles citing it.

Defense EvasionPrivilege Escalation
View on the matrix → Filter Detection Library MITRE official spec ↗
34Use cases
8Articles
12Sub-techniques
2Tactics

Sub-techniques (12)

Use cases covering this technique (34)

Cisco NVM - Non-Network Binary Making Network Connection ESCU actions · hunting P Cisco NVM - Suspicious Network Connection From Process With No Args ESCU actions · hunting P Create Remote Thread In Shell Application ESCU actions · alerting P DLLHost with no Command Line Arguments with Network ESCU actions · alerting P GPUpdate with no Command Line Arguments with Network ESCU actions · alerting P Notepad with no Command Line Arguments ESCU actions · alerting P Powershell Fileless Process Injection via GetProcAddress ESCU actions · alerting P Powershell Remote Thread To Known Windows Process ESCU actions · alerting P Rundll32 Create Remote Thread To A Process ESCU actions · alerting P Rundll32 CreateRemoteThread In Browser ESCU actions · alerting P SearchProtocolHost with no Command Line with Network ESCU actions · alerting P Suspicious DLLHost no Command Line Arguments ESCU actions · alerting P Suspicious GPUpdate no Command Line Arguments ESCU actions · alerting P Suspicious SearchProtocolHost no Command Line Arguments ESCU actions · alerting P Trickbot Named Pipe ESCU actions · alerting P Windows List ENV Variables Via SET Command From Uncommon Parent ESCU actions · hunting P Windows Process Injection In Non-Service SearchIndexer ESCU actions · alerting P Windows Process Injection Wermgr Child Process ESCU actions · hunting P Windows Process With NamedPipe CommandLine ESCU actions · hunting P Windows PUA Named Pipe ESCU actions · hunting P Windows Remote Assistance Spawning Process ESCU actions · alerting P Windows RMM Named Pipe ESCU actions · hunting P Windows Suspicious C2 Named Pipe ESCU actions · alerting P Windows Suspicious Named Pipe ESCU actions · alerting P Winhlp32 Spawning a Process ESCU actions · alerting P Wscript Or Cscript Suspicious Child Process ESCU actions · hunting P Cisco Secure Firewall - Communication Over Suspicious Ports ESCU actions · hunting P Cobalt Strike Named Pipes ESCU actions · alerting P Windows Command Shell Fetch Env Variables ESCU actions · alerting P [LLM] Talos weekly prevalent malware hash execution (Coinminer/Injector/Dropper.Miner) Bespoke install · alerting DSΣPDDCS [LLM] OneDrive.Sync.Service.exe spawned/injected outside legitimate OneDrive chain (SPECTRALVIPER injection target) Bespoke install · hunting DSPDDCS [LLM] csrss.exe or dwm.exe spawning child process (Win32K-GRFX kernel exploit marker) Bespoke exploit · alerting DSΣPDDCS [LLM] Talos weekly top-prevalent malware hash watch (Coinminer / Injector / W32.Variant) Bespoke install · alerting DSΣPDD [LLM] EDR-Freeze: WerFaultSecure.exe abused to suspend AV/EDR processes via MiniDumpWriteDump race Bespoke install · alerting DSΣP

Articles citing this technique (8)