TGViewer
APT APT @apt_notes · 16.7K subscribers
Post #983 4.6K

Forwarded from 1N73LL1G3NC3

🌐 The Pool Party You Will Never Forget: New Process Injection Techniques Using Windows Thread Pools

See how SafeBreach Labs Researchers developed a brand new set of highly flexible process injection techniques that are able to completely bypass leading endpoint detection and response (EDR) solutions.

💉 PoolParty

A collection of fully-undetectable process injection techniques abusing Windows Thread Pools.

PoolParty Variants:

1 - Overwrite the start routine of the target worker factory
2 - Insert TP_WORK work item to the target process's thread pool
3 - Insert TP_WAIT work item to the target process's thread pool
4 - Insert TP_IO work item to the target process's thread pool
5 - Insert TP_ALPC work item to the target process's thread pool
6 - Insert TP_JOB work item to the target process's thread pool
7 - Insert TP_DIRECT work item to the target process's thread pool
8 - Insert TP_TIMER work item to the target process's thread pool
  • 👍 11
  • ❤ 1
More from @apt_notes
  1. Sep 1, 2026🔒 Certi-Bhai — IIS AppPool → NT AUTHORITY\SYSTEM via AD CS RPC A webshell under IIS AppPo…
  2. Aug 17, 2026🔒 Citrix NetScaler Pre-Auth RCE (CVE-2026-8452) Unauthenticated heap overflow in SAML sig…
  3. Aug 11, 2026Post #1201
  4. Aug 7, 2026ResetNightmare ResetNightmare (CVE-2026-27912) is a validation flaw in the Kerberos Change…
  5. Jul 24, 2026🔒 Certighost (CVE-2026-54121) — AD CS Domain Controller Impersonation Low-privileged doma…
  6. Jul 9, 2026💉 P³ — Shellcode Loader: Process Parameter Poisoning This loader implements a code inject…
Threads Profile ViewerView any public Threads profile without an account.Open ThreadLook →Writing with AI? Make it sound human.Metric37 rewrites AI drafts so they read naturally. Free AI detector, 1,500 words free.Try Metric37 →