1200KM / simulation
T1055.004 Asynchronous Procedure Call — Attack Simulation
Adversaries may inject malicious code into processes via the asynchronous procedure call (APC) queue in order to evade process-based defenses as well as possibly elevate privileges. APC injection is a method of executing arbitrary code in the address space of a separate live process. APC injection is commonly performed by attaching malicious code to the APC Queue of a process's thread. Queued APC functions are executed when the thread enters an…
Technique description
Adversaries may inject malicious code into processes via the asynchronous procedure call (APC) queue in order to evade process-based defenses as well as possibly elevate privileges. APC injection is a method of executing arbitrary code in the address space of a separate live process. APC injection is commonly performed by attaching malicious code to the APC Queue of a process's thread. Queued APC functions are executed when the thread enters an…
At least one platform-compatible Atomic procedure is documented. Individual review, lab prerequisites, and validation remain required.
Official ATT&CK definition · Detection rules and anomaly models
Documented simulation candidates
- Remote Process Injection with Go using NtQueueApcThreadEx WinAPI
Procedure 4cc571b1-f450-414a-850f-879baf36aa06; elevation not declared required; cleanup present, not reviewed. Not executed or individually validated.
- Process Injection via C#
Procedure 611b39b7-e243-4c81-87a4-7145a90358b1; elevation not declared required; cleanup not declared. Not executed or individually validated.
- EarlyBird APC Queue Injection in Go
Procedure 73785dd2-323b-4205-ab16-bb6f06677e14; elevation not declared required; cleanup present, not reviewed. Not executed or individually validated.
Connected ecosystem references
Linked tags
Detection and collection
Attack tools
No reviewed association in this snapshot.
Threat actor context
These are explicit actor-to-technique associations in the existing Threat Matrix snapshot, not attribution of an event or proof that a detector identifies the actor. No tool-to-actor relationship is inferred.
Existing research
Pinned research references. No browser attack runner, live simulation result or validated detector is asserted. Source mappings and validation limits are preserved. ATT&CK / Atomic provenance · Detection provenance.