Windows Console Named-Pipe Injection Skips Common EDR APIs
Reports describe Windows console named-pipe injection that avoids VirtualAllocEx and WriteProcessMemory while still changing protection and thread context.
Security researcher Two Seven One Three disclosed console named-pipe injection, a Windows process-injection method that delivers bytes through a redirected standard-input pipe of a console child such as nslookup.exe or netsh.exe instead of VirtualAllocEx and WriteProcessMemory. The injector locates a marker in the child, uses VirtualProtectEx to mark those pages executable, suspends a thread, and redirects its instruction pointer. A demonstration in the first report found 368 bytes inside nslookup.exe and changed the region from read-write to executable. Payloads must omit carriage return, line feed, and Ctrl+Z; the second report states more generally that console control characters can disrupt delivery. The sources disagree on attribution: one names Two Seven One Three, while the other refers only to researchers and adds a citation to earlier SensePost work on process-parameter poisoning. Both say single-API alerts can miss the technique and recommend correlating console launches, pipe writes, remote executable-memory changes, and thread-context edits.
- Security researcher Two Seven One Three disclosed console named-pipe injection; a later report attributes it only to unnamed researchers.
- The method starts a console child such as nslookup.exe or netsh.exe and writes payload bytes through a redirected standard-input pipe, avoiding VirtualAllocEx and WriteProcessMemory.
- The injector locates a marker, calls VirtualProtectEx to make those pages executable, suspends a thread, and redirects its instruction pointer.
- A demonstration found 368 bytes inside nslookup.exe and changed that region from read-write to executable.
- Payloads must omit carriage return, line feed, and Ctrl+Z; the second report says console control characters can break delivery.
- Both reports urge correlating process creation, pipe activity, remote protection changes, and thread-context edits rather than single-API alerts.
- The later report cites earlier SensePost work on process-parameter poisoning.
Coverage timelineoldest first · each row is one article
- · 17h agoNew Windows Process Injection Attack Evades EDR Monitoring Without WriteProcessMemory
Cyber Security News· 56
Researcher details Windows console named-pipe injection that avoids VirtualAllocEx and WriteProcessMemory EDR checks.
- · 4h agoNew Windows Process Injection Technique Bypasses EDR Monitoring Without WriteProcessMemory
GBHackers· 58
Researchers disclosed a Windows console-pipe injection method that avoids WriteProcessMemory and VirtualAllocEx.