Process Injection: From Classic DLL to Process Hollowing and .NET Reflection
A comprehensive map of Windows process injection techniques: for every technique from classic DLL injection to process hollowing, Doppelgänging, APC/Early Bird, and .NET reflective assembly loading — the API chain, Sysmon/ETW detection, and defensive triad. A technical reference for red/purple team and SOC/DFIR teams.
Swipe or use the arrows to move between sections
Zafiyet (Vulnerability)
Tehdit bağlamı, zafiyet ve istismar senaryosu
This section is not open yet
Titles and summaries are free. The detail of this section is not published yet. You can request the offline comparison tool for the open environments with a company email.
Request the offline tool →Prevention & Hardening
Savunma teknolojileri, policy ve sertleştirme
This section is not open yet
Titles and summaries are free. The detail of this section is not published yet. You can request the offline comparison tool for the open environments with a company email.
Request the offline tool →Detection
Davranış, loglama ve detection kuralları
This section is not open yet
Titles and summaries are free. The detail of this section is not published yet. You can request the offline comparison tool for the open environments with a company email.
Request the offline tool →