1200KM / simulation
T1055.012 Process Hollowing — Attack Simulation
Adversaries may inject malicious code into suspended and hollowed processes in order to evade process-based defenses. Process hollowing is a method of executing arbitrary code in the address space of a separate live process. Process hollowing is commonly performed by creating a process in a suspended state then unmapping/hollowing its memory, which can then be replaced with malicious code. A victim process can be created with native Windows API…
Technique description
Adversaries may inject malicious code into suspended and hollowed processes in order to evade process-based defenses. Process hollowing is a method of executing arbitrary code in the address space of a separate live process. Process hollowing is commonly performed by creating a process in a suspended state then unmapping/hollowing its memory, which can then be replaced with malicious code. A victim process can be created with native Windows API…
At least one platform-compatible Atomic procedure is documented. Individual review, lab prerequisites, and validation remain required.
Official ATT&CK definition · Detection rules and anomaly models
Documented simulation candidates
- RunPE via VBA
Procedure 3ad4a037-1598-4136-837c-4027e4fa319b; elevation not declared required; cleanup not declared. Not executed or individually validated.
- Process Hollowing using PowerShell
Procedure 562427b4-39ef-4e8c-af88-463a78e70b9c; elevation not declared required; cleanup present, not reviewed. Not executed or individually validated.
- Process Hollowing in Go using CreateProcessW and CreatePipe WinAPIs (T1055.012)
Procedure 94903cc5-d462-498a-b919-b1e5ab155fee; elevation not declared required; cleanup present, not reviewed. Not executed or individually validated.
- Process Hollowing in Go using CreateProcessW WinAPI
Procedure c8f98fe1-c89b-4c49-a7e3-d60ee4bc2f5a; elevation not declared required; cleanup present, not reviewed. Not executed or individually validated.
Connected ecosystem references
Linked tags
Detection and collection
Attack tools
Threat actor context
These are explicit actor-to-technique associations in the existing Threat Matrix snapshot, not attribution of an event or proof that a detector identifies the actor. No tool-to-actor relationship is inferred.
Existing research
Pinned research references. No browser attack runner, live simulation result or validated detector is asserted. Source mappings and validation limits are preserved. ATT&CK / Atomic provenance · Detection provenance.