Analytics BIOC
Low
✕
Uncommon NtWriteVirtualMemoryRemote API invocation with a PE header buffer
A process wrote a PE header to another process by calling the NtWriteVirtualMemoryRemote API function.
- Module:
- Platform Analytics
- Data source:
- XDR Agent with eXtended Threat Hunting (XTH)
ATT&CK tactics: Defense Evasion (TA0005) Privilege Escalation (TA0004)
ATT&CK techniques: Process Injection: Portable Executable Injection (T1055.002)
Detector tags: Injection Analytics
Attacker's goals:
Gain code execution on the host in the context of another process.
Investigative actions:
Investigate the acting process for other malicious activities. Check if the target process was injected and for anomalies in its behavior after this event.
- Test period:
- N/A (single event)
- Deduplication:
- 1 Day
4 variations:
- Uncommon NtWriteVirtualMemoryRemote API invocation with a PE header buffer from an office process High (parent: Low)
- Uncommon NtWriteVirtualMemoryRemote API invocation with a PE header buffer from an injected thread Medium (parent: Low)
- Uncommon NtWriteVirtualMemoryRemote API invocation with a PE header buffer from a LOLBIN process Medium (parent: Low)
- Uncommon NtWriteVirtualMemoryRemote API invocation with a PE header buffer from an unsigned process Medium (parent: Low)