Open cardosec

Case 91CA77 · Malware & intel · L4 Advanced

Process injection

Practise as: Explain it
  1. 01 What is it?
  2. 02 How is it abused?
  3. 03 How do you stop it?
What a strong answer covers

Try it out loud first. Then check yourself:

  1. Running code inside another process to evade defenses and inherit its privileges and network trust
  2. Classic chain: OpenProcess, VirtualAllocEx, WriteProcessMemory, CreateRemoteThread
  3. Variants: process hollowing, APC injection, reflective DLL loading, thread execution hijacking
  4. Detect via Sysmon Event 8 (CreateRemoteThread) and 10 (ProcessAccess), plus RWX memory not backed by a file
  5. EDRs hook ntdll or use kernel ETW-TI; attackers answer with direct/indirect syscalls and unhooking

If the interviewer pushes back

  • Why is unbacked executable memory such a strong signal, and when is it a false positive?

Go deeper

cardosec draws a security topic and gives you a clock: explain it out loud with no notes, then see what you covered and what you missed. Free during early access.