Process Injection
Definition
A technique used by malware and attackers to execute code inside the address space of a legitimate running process. Common methods include CreateRemoteThread, APC injection, and reflective DLL loading. The injected code inherits the host process's privileges and is invisible to filesystem scanners.
- Category
- Malware evasion / execution technique
- Common methods
- CreateRemoteThread, APC, reflective DLL
- Effect
- Runs inside a legitimate process's memory
- Evasion
- Invisible to filesystem scanners
Common questions
Why does process injection evade filesystem-based antivirus scanning?+
The malicious code is injected directly into the memory of an already-running legitimate process rather than written to disk as its own executable file, so a scanner that only checks files on disk never encounters it, which is why memory forensics and behavioural detection are needed to catch it.
How would a forensic analyst detect process injection during memory analysis?+
The analyst looks for anomalies such as executable memory regions inside a process that do not correspond to any loaded module on disk, unexpected threads whose start address falls outside known DLLs, or a legitimate process exhibiting network or file behaviour inconsistent with its normal role.
Related terms
- LiME (Linux Memory Extractor)
- A loadable kernel module that acquires physical memory from Linux, macOS, and Android systems. It maps the physical address space and either...
- Order of Volatility
- The sequence in which digital evidence should be collected, ranked from most to least transient. Defined in RFC 3227. CPU registers and...
- Physical Memory Image
- A byte-for-byte copy of all installed RAM on a running system, acquired at the hardware or kernel level. Contains all data structures,...
- Reflective DLL Loading
- A technique that loads a Windows DLL directly from memory without registering it with the OS loader. The DLL resolves its own...
- Volatility Framework
- An open-source memory forensics framework written in Python. It parses raw memory images using OS-specific symbol information to reconstruct kernel data structures...