1200KM / simulation
T1055.009 Proc Memory — Attack Simulation
Adversaries may inject malicious code into processes via the /proc filesystem in order to evade process-based defenses as well as possibly elevate privileges. Proc memory injection is a method of executing arbitrary code in the address space of a separate live process. Proc memory injection involves enumerating the memory of a process via the /proc filesystem (/proc/[pid]) then crafting a return-oriented programming (ROP) payload with available…
Technique description
Adversaries may inject malicious code into processes via the /proc filesystem in order to evade process-based defenses as well as possibly elevate privileges. Proc memory injection is a method of executing arbitrary code in the address space of a separate live process. Proc memory injection involves enumerating the memory of a process via the /proc filesystem (/proc/[pid]) then crafting a return-oriented programming (ROP) payload with available…
At least one platform-compatible Atomic procedure is documented. Individual review, lab prerequisites, and validation remain required.
Official ATT&CK definition · Detection rules and anomaly models
Documented simulation candidates
- ROP chain Mprotect Return Address Overwrite
Procedure 3d9e332e-60c9-407a-af4c-a9ae43c4f1d0; elevation not declared required; cleanup present, not reviewed. Not executed or individually validated.
- Instruction Overwrite Jump
Procedure 3f452c87-25b5-47c0-81d8-01908df1b927; elevation not declared required; cleanup present, not reviewed. Not executed or individually validated.
- GOT Injection
Procedure 4383bbd3-aa6c-49fd-a1a9-cf112c95982c; elevation not declared required; cleanup present, not reviewed. Not executed or individually validated.
- Inplace Instruction Overwrite
Procedure 50859b3b-b088-4c7b-973d-03a0365a9bf9; elevation not declared required; cleanup present, not reviewed. Not executed or individually validated.
- Return Address Overwrite for full ROP chain execution
Procedure 5696f417-30e5-4942-988d-0b9dcfe3a929; elevation not declared required; cleanup present, not reviewed. Not executed or individually validated.
- Return Address Overwrite
Procedure 5fabf878-7dd4-48d3-9995-408fac68e166; elevation not declared required; cleanup present, not reviewed. Not executed or individually validated.
Connected ecosystem references
Linked tags
Detection and collection
Attack tools
No reviewed association in this snapshot.
Existing research
Pinned research references. No browser attack runner, live simulation result or validated detector is asserted. Source mappings and validation limits are preserved. ATT&CK / Atomic provenance · Detection provenance.