New Windows Process Injection Attack Evades EDR Monitoring Without WriteProcessMemory
Researcher details Windows console named-pipe injection that avoids VirtualAllocEx and WriteProcessMemory EDR checks.
Security researcher Two Seven One Three disclosed console named-pipe injection, a Windows process-injection method that avoids VirtualAllocEx and WriteProcessMemory. An injector starts a console child such as nslookup.exe or netsh.exe, writes the payload through a redirected standard-input pipe, locates a marker in memory, calls VirtualProtectEx to make those pages executable, then suspends a thread and redirects its instruction pointer. A demonstration found 368 bytes inside nslookup.exe and changed the region from read-write to executable. Payloads must omit carriage return, line feed, and Ctrl+Z, and the write-up urges correlation of creation, handles, protection changes, and thread context rather than single-API alerts.