Skip to content

Process Injection

Definition

A technique used by malware and attackers to execute code inside the address space of a legitimate running process. Common methods include CreateRemoteThread, APC injection, and reflective DLL loading. The injected code inherits the host process's privileges and is invisible to filesystem scanners.

Category
Malware evasion / execution technique
Common methods
CreateRemoteThread, APC, reflective DLL
Effect
Runs inside a legitimate process's memory
Evasion
Invisible to filesystem scanners

Common questions

Why does process injection evade filesystem-based antivirus scanning?+

The malicious code is injected directly into the memory of an already-running legitimate process rather than written to disk as its own executable file, so a scanner that only checks files on disk never encounters it, which is why memory forensics and behavioural detection are needed to catch it.

How would a forensic analyst detect process injection during memory analysis?+

The analyst looks for anomalies such as executable memory regions inside a process that do not correspond to any loaded module on disk, unexpected threads whose start address falls outside known DLLs, or a legitimate process exhibiting network or file behaviour inconsistent with its normal role.

Related terms

LiME (Linux Memory Extractor)
A loadable kernel module that acquires physical memory from Linux, macOS, and Android systems. It maps the physical address space and either...
Order of Volatility
The sequence in which digital evidence should be collected, ranked from most to least transient. Defined in RFC 3227. CPU registers and...
Physical Memory Image
A byte-for-byte copy of all installed RAM on a running system, acquired at the hardware or kernel level. Contains all data structures,...
Reflective DLL Loading
A technique that loads a Windows DLL directly from memory without registering it with the OS loader. The DLL resolves its own...
Volatility Framework
An open-source memory forensics framework written in Python. It parses raw memory images using OS-specific symbol information to reconstruct kernel data structures...

Explained in

Your journey to becoming a forensic professional starts here.

Practice with mock tests, learn from structured notes, and get your questions answered by a global forensic community, all in one place.