A comprehensive map of Windows process injection techniques: for every technique from classic DLL injection to process hollowing, Doppelgänging, APC/Early Bird, and .NET reflective assembly loading — the API chain, Sysmon/ETW detection, and defensive triad. A technical reference for red/purple team and SOC/DFIR teams.
Technique Library
MITRE ATT&CK-based attack techniques — Exploit · Prevention · Detection
3 techniques · defense evasion
Clear filters ×Explains how modern EDRs use userland API hooks, kernel callbacks, and ETW telemetry; how attackers target these layers via direct/indirect syscall, NTDLL unhooking, ETW/AMSI patching, and call stack spoofing; and how defenders detect these with ETW-TI, kernel call stack analysis, and telemetry integrity monitoring. ATT&CK: T1562.001, T1106, T1027.007, T1620, T1574.013.
A comprehensive map of AD trust architecture attacks: parent-child intra-forest ExtraSids escalation, trust key theft and forged inter-realm TGT generation, SID history injection, cross-forest Kerberoasting, TGT delegation (KB4490425), and foreign security principals. Event-based and behavioral detection for SOC/DFIR, SID filtering validation, and tier-0 hardening.