🌐 The Pool Party You Will Never Forget: New Process Injection Techniques Using Windows Thread Pools
See how SafeBreach Labs Researchers developed a brand new set of highly flexible process injection techniques that are able to completely bypass leading endpoint detection and response (EDR) solutions.
💉 PoolParty
A collection of fully-undetectable process injection techniques abusing Windows Thread Pools.
PoolParty Variants:
1 - Overwrite the start routine of the target worker factory
2 - Insert TP_WORK work item to the target process's thread pool
3 - Insert TP_WAIT work item to the target process's thread pool
4 - Insert TP_IO work item to the target process's thread pool
5 - Insert TP_ALPC work item to the target process's thread pool
6 - Insert TP_JOB work item to the target process's thread pool
7 - Insert TP_DIRECT work item to the target process's thread pool
8 - Insert TP_TIMER work item to the target process's thread pool
Post #983
4.6K
Forwarded from 1N73LL1G3NC3
- 👍 11
- ❤ 1