New Windows Process Injection Technique Bypasses EDR Monitoring Without WriteProcessMemory
Researchers disclosed a Windows console-pipe injection method that avoids WriteProcessMemory and VirtualAllocEx.
Researchers disclosed console named-pipe injection, a Windows process-injection method that moves data into a child console process through redirected standard input instead of the commonly monitored VirtualAllocEx and WriteProcessMemory APIs. The write-up says the injector still changes memory protection in the child and redirects a thread, so single-API alerts can miss it. Certain console control characters can break delivery. The article cites earlier SensePost work on process-parameter poisoning and urges correlation of unusual console launches, pipe writes, remote executable-memory changes, and thread-context edits.