New Windows Process Injection Technique Bypasses EDR Monitoring Without WriteProcessMemory

A newly disclosed method for Windows process injection utilizes redirected console input and named pipes to transfer payload data into a child process without invoking the heavily monitored APIs VirtualAllocEx and WriteProcessMemory. This technique, called console named-pipe injection, highlights the need for endpoint defenses to correlate events across processes, memory protection, thread context, and interprocess […]

This article has been indexed from GBHackers Security | #1 Globally Trusted Cyber Security News Platform

Read the original article: