1200KM / simulation
T1055 Process Injection — Attack Simulation
Adversaries may inject code into processes in order to evade process-based defenses as well as possibly elevate privileges. Process injection is a method of executing arbitrary code in the address space of a separate live process. Running code in the context of another process may allow access to the process's memory, system/network resources, and possibly elevated privileges. Execution via process injection may also evade detection from…
Technique description
Adversaries may inject code into processes in order to evade process-based defenses as well as possibly elevate privileges. Process injection is a method of executing arbitrary code in the address space of a separate live process. Running code in the context of another process may allow access to the process's memory, system/network resources, and possibly elevated privileges. Execution via process injection may also evade detection from…
At least one platform-compatible Atomic procedure is documented. Individual review, lab prerequisites, and validation remain required.
Official ATT&CK definition · Detection rules and anomaly models
Documented simulation candidates
- UUID custom process Injection
Procedure 0128e48e-8c1a-433a-a11a-a5304734f1e1; elevation required; cleanup present, not reviewed. Not executed or individually validated.
- Read-Write-Execute process Injection
Procedure 0128e48e-8c1a-433a-a11a-a5387384f1e1; elevation required; cleanup present, not reviewed. Not executed or individually validated.
- Shellcode execution via VBA
Procedure 1c91e740-1729-4329-b779-feba6e71d048; elevation not declared required; cleanup not declared. Not executed or individually validated.
- Process Injection with Go using UuidFromStringA WinAPI
Procedure 2315ce15-38b6-46ac-a3eb-5e21abef2545; elevation not declared required; cleanup present, not reviewed. Not executed or individually validated.
- Process Injection with Go using CreateThread WinAPI
Procedure 2871ed59-3837-4a52-9107-99500ebc87cb; elevation not declared required; cleanup present, not reviewed. Not executed or individually validated.
- Process Injection with Go using CreateThread WinAPI (Natively)
Procedure 2a3c7035-d14f-467a-af94-933e49fe6786; elevation not declared required; cleanup present, not reviewed. Not executed or individually validated.
- Remote Process Injection with Go using CreateRemoteThread WinAPI (Natively)
Procedure 2a4ab5c1-97ad-4d6d-b5d3-13f3a6c94e39; elevation not declared required; cleanup present, not reviewed. Not executed or individually validated.
- Remote Process Injection in LSASS via mimikatz
Procedure 3203ad24-168e-4bec-be36-f79b13ef8a83; elevation not declared required; cleanup not declared. Not executed or individually validated.
- Dirty Vanity process Injection
Procedure 49543237-25db-497b-90df-d0a0a6e8fe2c; elevation not declared required; cleanup present, not reviewed. Not executed or individually validated.
- Remote Process Injection with Go using CreateRemoteThread WinAPI
Procedure 69534efc-d5f5-4550-89e6-12c6457b9edd; elevation not declared required; cleanup present, not reviewed. Not executed or individually validated.
- Process Injection with Go using EtwpCreateEtwThread WinAPI
Procedure 7362ecef-6461-402e-8716-7410e1566400; elevation not declared required; cleanup present, not reviewed. Not executed or individually validated.
- Remote Process Injection with Go using RtlCreateUserThread WinAPI
Procedure a0c1725f-abcd-40d6-baac-020f3cf94ecd; elevation not declared required; cleanup present, not reviewed. Not executed or individually validated.
- Section View Injection
Procedure c6952f41-6cf0-450a-b352-2ca8dae7c178; elevation not declared required; cleanup present, not reviewed. Not executed or individually validated.
Connected ecosystem references
Linked tags
Detection and collection
Attack tools
Threat actor context
These are explicit actor-to-technique associations in the existing Threat Matrix snapshot, not attribution of an event or proof that a detector identifies the actor. No tool-to-actor relationship is inferred.
Existing research
Connected anomaly research
Curated research views reached through an exact source technique, a catalog model, or a reviewed collection reference. These are navigation associations, not claims of detector effectiveness or sensor equivalence.
Telemetry contracts · Maintained query examples · Validation and blind spots
Pinned research references. No browser attack runner, live simulation result or validated detector is asserted. Source mappings and validation limits are preserved. ATT&CK / Atomic provenance · Detection provenance.