1200KM / detection
T1055.011 Extra Window Memory Injection — Detection Rules
Detection workspace for T1055.011 Extra Window Memory Injection: 1 Sigma sources, 0 Atlas concepts and 0 anomaly models. No live detection validation.
Source-backed rule directory
- Uncommon Process Access Rights For Target Image · test · low · {"category":"process_access","product":"windows"}
Atlas deterministic concepts
No exact concept selected.
Anomaly models
No exact Atlas model in this snapshot.
ATT&CK analytic guidance
DET0217 Detection Strategy for Extra Window Memory (EWM) Injection on Windows
AN0608 Analytic 0608
Detects adversary manipulation of Extra Window Memory (EWM) in a GUI process, where the attacker uses SetWindowLong or SetClassLong to redirect function pointers to injected shellcode stored in shared memory, then triggers execution via a window message like SendNotifyMessage.
Connected ecosystem references
Linked tags
Simulation, tools and telemetry
T1055.011 simulation workspace
No reviewed association in this snapshot.
Existing anomaly research
Pinned research references. No browser attack runner, live simulation result or validated detector is asserted. Source mappings and validation limits are preserved. ATT&CK / Atomic provenance · Detection provenance.