What it does. Detect process hollowing (MITRE T1055.012) by analyzing memory-mapped Part of mukul975/Anthropic-Cybersecurity-Skills (817 security skills) (mukul975/Anthropic-Cybersecurity-Skills).
Install
npx skills add mukul975/Anthropic-Cybersecurity-Skills --skill detecting-process-hollowing-technique, or copy the skill folder into ~/.claude/skills/detecting-process-hollowing-technique/.
- Raw file:
curl -sL https://raw.githubusercontent.com/mukul975/Anthropic-Cybersecurity-Skills/HEAD/skills/detecting-process-hollowing-technique/SKILL.md
SKILL.md (verbatim)
name: detecting-process-hollowing-technique
description: Detect process hollowing (MITRE T1055.012) by analyzing memory-mapped
sections, hollowed process indicators, and parent-child anomalies using EDR
telemetry, Volatility's malfind plugin, pe-sieve, Hollows Hunter, and Sysmon
Event ID 25. Use when investigating a legitimate-looking process (svchost.exe,
explorer.exe, rundll32.exe) suspected of hosting injected code via
NtUnmapViewOfSection.
domain: cybersecurity
subdomain: threat-hunting
tags:
- threat-hunting
- mitre-attack
- process-hollowing
- process-injection
- edr
- t1055
- proactive-detection
version: '1.0'
author: mahipal
license: Apache-2.0
d3fend_techniques:
- Platform Monitoring
- Process Code Segment Verification
- Segment Address Offset Randomization
- Process Analysis
- Application Hardening
nist_csf:
- DE.CM-01
- DE.AE-02
- DE.AE-07
- ID.RA-05
mitre_attack:
- T1046
- T1057
- T1082
- T1083
- T1055
Detecting Process Hollowing Technique
When to Use
- When investigating suspected fileless malware or in-memory threats
- After EDR alerts on process injection or suspicious memory operations
- When hunting for defense evasion techniques in a compromised environment
- When threat intel reports indicate process hollowing in active campaigns
- During purple team exercises validating T1055.012 detection coverage
Prerequisites
- EDR with memory protection monitoring (CrowdStrike, MDE, SentinelOne)
- Sysmon with Event IDs 1 (Process Create), 8 (CreateRemoteThread), 25 (ProcessTampering)
- Windows ETW providers for process hollowing (Microsoft-Windows-Kernel-Process)
- Memory forensics capabilities (Volatility, WinDbg)
- Process integrity monitoring tools
Workflow
- Understand Hollowing Mechanics: Process hollowing involves creating a legitimate process in suspended state, unmapping its memory, writing malicious code, then resuming execution.
- Monitor Suspended Process Creation: Hunt for processes created with CREATE_SUSPENDED flag followed by memory writes and thread resumption.
- Detect Memory Section Anomalies: Identify processes where the in-memory image differs from the on-disk binary (image mismatch).
- Analyze Parent-Child Process Trees: Flag processes whose behavior does not match their binary name (e.g., svchost.exe making unusual network connections).
- Check Process Integrity: Compare process memory sections against the legitimate binary on disk.
- Correlate with Network Activity: Hollowed processes often establish C2 connections - correlate suspicious process behavior with network logs.
- Document and Contain: Report findings, isolate affected endpoints, and update detection rules.
Key Concepts
| Concept |
Description |
| T1055.012 |
Process Injection: Process Hollowing |
| T1055 |
Process Injection (parent technique) |
| T1055.001 |
DLL Injection |
| T1055.003 |
Thread Execution Hijacking |
| T1055.004 |
Asynchronous Procedure Call |
| CREATE_SUSPENDED |
Windows flag to create a process in suspended state |
| NtUnmapViewOfSection |
API to unmap process memory sections |
| WriteProcessMemory |
API to write into another process's memory |
| ResumeThread |
API to resume a suspended thread |
| Image Mismatch |
Process memory content differs from on-disk binary |
| Process Doppelganging |
Related technique using NTFS transactions (T1055.013) |
| Tool |
Purpose |
| CrowdStrike Falcon |
Memory protection and hollowing detection |
| Microsoft Defender for Endpoint |
ProcessTampering alerts |
| Sysmon v13+ |
Event ID 25 ProcessTampering detection |
| Volatility |
Memory forensics - malfind plugin |
| pe-sieve |
Process memory scanner for hollowed processes |
| Hollows Hunter |
Automated hollowed process detection |
| Process Hacker |
Live process memory inspection |
| API Monitor |
Monitor NtUnmapViewOfSection calls |
Common Scenarios
- Svchost.exe Hollowing: Malware creates svchost.exe suspended, hollows it, injects backdoor code - process appears legitimate but behaves maliciously.
- Explorer.exe Hollowing: Attacker hollows explorer.exe to inherit its network permissions and trusted process context.
- Rundll32 Hollowing: Malicious loader creates rundll32.exe, replaces its memory with implant code for C2 beaconing.
- Multi-Stage Hollowing: Loader uses process hollowing as first stage, then performs additional injection into services.
Hunt ID: TH-HOLLOW-[DATE]-[SEQ]
Technique: T1055.012
Hollowed Process: [Process name and PID]
Original Binary: [Expected on-disk path]
Parent Process: [Parent name and PID]
Memory Mismatch: [Yes/No]
Suspicious APIs: [NtUnmapViewOfSection, WriteProcessMemory, etc.]
Network Activity: [C2 connections if any]
Host: [Hostname]
User: [Account context]
Risk Level: [Critical/High/Medium/Low]
Other files in this skill
assets/template.md (verbatim)
Process Hollowing Hunt Template
| Field |
Value |
| Hunt ID |
TH-HOLLOW-YYYY-MM-DD-NNN |
| Analyst |
|
| Date |
|
| Status |
[ ] In Progress / [ ] Complete |
Hypothesis
[e.g., "Adversaries have used process hollowing to inject malicious code into svchost.exe instances to evade detection."]
Findings
| # |
Host |
Process |
Parent |
Expected Parent |
Network Activity |
Risk |
Verdict |
| 1 |
|
|
|
|
|
|
|
Memory Analysis Results
| Process (PID) |
Image Mismatch |
Injected Code |
VAD Anomaly |
Verdict |
|
|
|
|
|
Recommendations
- Memory Dump: [Collect memory from affected hosts]
- Containment: [Isolate compromised endpoints]
- Detection: [Deploy Sysmon v13+ with Event ID 25]
- Prevention: [Enable Attack Surface Reduction rules]
references/api-reference.md (verbatim)
API Reference: Detecting Process Hollowing Technique
Process Hollowing API Sequence
| Step |
API Call |
Purpose |
| 1 |
CreateProcess(SUSPENDED) |
Create target suspended |
| 2 |
NtUnmapViewOfSection |
Unmap legitimate code |
| 3 |
VirtualAllocEx |
Allocate for payload |
| 4 |
WriteProcessMemory |
Write malicious code |
| 5 |
SetThreadContext |
Redirect execution |
| 6 |
ResumeThread |
Execute payload |
Commonly Hollowed Processes
| Process |
Reason |
| svchost.exe |
Trusted, always running |
| explorer.exe |
UI process |
| notepad.exe |
Simple, rarely monitored |
| dllhost.exe |
COM surrogate |
Sysmon Detection Events
| Event ID |
Detection |
| 1 |
Suspicious parent-child |
| 8 |
CreateRemoteThread into hollowed target |
| 10 |
Process Access with PROCESS_ALL_ACCESS |
Splunk SPL
index=sysmon EventCode=10
| where TargetImage IN ("*\svchost.exe","*\explorer.exe")
| where GrantedAccess IN ("0x1FFFFF","0x1F3FFF")
| table _time SourceImage TargetImage GrantedAccess Computer
CLI Usage
python agent.py --sysmon-log Sysmon.evtx
references/standards.md (verbatim)
Standards and References - Process Hollowing Detection
MITRE ATT&CK Mappings
T1055.012 - Process Injection: Process Hollowing
- Tactic: Defense Evasion (TA0005), Privilege Escalation (TA0004)
- Platforms: Windows
- Data Sources: Process modification, OS API execution, Process access
| Sub-Technique |
Name |
| T1055.001 |
Dynamic-link Library Injection |
| T1055.002 |
Portable Executable Injection |
| T1055.003 |
Thread Execution Hijacking |
| T1055.004 |
Asynchronous Procedure Call |
| T1055.005 |
Thread Local Storage |
| T1055.008 |
Ptrace System Calls |
| T1055.009 |
Proc Memory |
| T1055.011 |
Extra Window Memory Injection |
| T1055.012 |
Process Hollowing |
| T1055.013 |
Process Doppelganging |
| T1055.014 |
VDSO Hijacking |
| T1055.015 |
ListPlanting |
Process Hollowing API Call Sequence
1. CreateProcess(CREATE_SUSPENDED) -> Create target in suspended state
2. NtQueryInformationProcess -> Get PEB address
3. ReadProcessMemory(PEB) -> Read image base from PEB
4. NtUnmapViewOfSection(ImageBase) -> Unmap original image
5. VirtualAllocEx(ImageBase, size) -> Allocate memory at same base
6. WriteProcessMemory(PE headers) -> Write malicious PE headers
7. WriteProcessMemory(PE sections) -> Write malicious code sections
8. SetThreadContext(EntryPoint) -> Set new entry point
9. ResumeThread -> Resume execution with malicious code
Detection Data Sources
| Source |
Event/Indicator |
Description |
| Sysmon Event 1 |
Process Create |
Process created with suspicious parent |
| Sysmon Event 8 |
CreateRemoteThread |
Remote thread in target process |
| Sysmon Event 25 |
ProcessTampering |
Image file replaced (Sysmon v13+) |
| ETW |
Microsoft-Windows-Kernel-Process |
Kernel-level process events |
| MDE |
ProcessTampering |
AlertType for hollowing detection |
| Memory |
Malfind |
Volatility plugin for injected code |
| Memory |
VAD analysis |
Virtual Address Descriptor anomalies |
Volatility Forensic Commands
# Detect injected/hollowed processes
volatility -f memory.dmp --profile=Win10x64 malfind
# Compare process memory to disk image
volatility -f memory.dmp --profile=Win10x64 procdump -p <PID> -D ./dump/
# Analyze process memory sections
volatility -f memory.dmp --profile=Win10x64 vadinfo -p <PID>
# Check process image path vs loaded modules
volatility -f memory.dmp --profile=Win10x64 dlllist -p <PID>
Known Malware Using Process Hollowing
| Malware |
Target Process |
Notes |
| Emotet |
Multiple |
Uses hollowing for persistence |
| TrickBot |
svchost.exe |
Hollows svchost for C2 |
| Dridex |
explorer.exe |
Financial trojan |
| FormBook |
Various |
Infostealer using hollowing |
| AgentTesla |
RegAsm.exe, MSBuild.exe |
Targets .NET processes |
| Remcos |
Common utilities |
RAT using hollowing |
| NanoCore |
Various |
RAT with hollowing capability |
| AsyncRAT |
Various .NET processes |
Open-source RAT |
references/workflows.md (verbatim)
Detailed Hunting Workflow - Process Hollowing Detection
Phase 1: Sysmon-Based Detection
Step 1.1 - Process Tampering Events (Sysmon v13+)
index=sysmon EventCode=25
| table _time Computer User Image Type
| sort -_time
Step 1.2 - Suspicious Process Creation Patterns
index=sysmon EventCode=1
| where match(Image, "(?i)(svchost|explorer|rundll32|dllhost|conhost|taskhost)\.exe$")
| where NOT match(ParentImage, "(?i)(services\.exe|explorer\.exe|svchost\.exe|userinit\.exe|winlogon\.exe)")
| table _time Computer User Image ParentImage CommandLine
Step 1.3 - KQL for MDE ProcessTampering
DeviceEvents
| where ActionType == "ProcessTampering"
| project Timestamp, DeviceName, FileName, ProcessCommandLine,
InitiatingProcessFileName, InitiatingProcessCommandLine, AdditionalFields
| order by Timestamp desc
Phase 2: Parent-Child Process Validation
Step 2.1 - Invalid Parent-Child Relationships
Known legitimate parent-child pairs:
- services.exe -> svchost.exe
- explorer.exe -> user applications
- winlogon.exe -> userinit.exe
- svchost.exe -> specific service children
index=sysmon EventCode=1
| eval expected_parent=case(
match(Image,"(?i)svchost\.exe$"), "services.exe",
match(Image,"(?i)taskhost\.exe$"), "svchost.exe",
match(Image,"(?i)userinit\.exe$"), "winlogon.exe",
match(Image,"(?i)smss\.exe$"), "System",
1=1, "any"
)
| eval parent_name=mvindex(split(ParentImage,"\\"),-1)
| where expected_parent!="any" AND NOT match(parent_name, expected_parent)
| table _time Computer Image ParentImage expected_parent parent_name CommandLine
Phase 3: Memory Analysis
Step 3.1 - pe-sieve Scanning
# Scan all processes for hollowing
Get-Process | ForEach-Object {
$pid = $_.Id
& pe-sieve64.exe /pid $pid /shellc /dmode 1 /json
}
Step 3.2 - Hollows Hunter Full Scan
# Run Hollows Hunter for automated detection
hollows_hunter64.exe /loop /json /dir C:\hunt_output
Step 3.3 - Volatility Malfind
# Detect injected/modified process memory
python vol.py -f memory.raw windows.malfind
# Dump suspicious processes
python vol.py -f memory.raw windows.pslist --dump
Phase 4: Behavioral Analysis
Step 4.1 - Process Behavior Mismatches
Look for processes whose network/file behavior contradicts their identity:
index=sysmon EventCode=3
| where match(Image, "(?i)(svchost|dllhost|taskhost|conhost)\.exe$")
| where NOT match(DestinationIp, "^(10\.|172\.(1[6-9]|2[0-9]|3[01])\.|192\.168\.)")
| where DestinationPort NOT IN (53, 80, 443, 123)
| stats count by Image DestinationIp DestinationPort Computer
Step 4.2 - Hollowed Process C2 Indicators
index=sysmon EventCode=3
| where match(Image, "(?i)(svchost|explorer|rundll32)\.exe$")
| bin _time span=1s
| streamstats current=f last(_time) as prev by Image Computer DestinationIp
| eval interval=_time-prev
| stats count avg(interval) as avg_interval stdev(interval) as sd by Image Computer DestinationIp
| eval cv=sd/avg_interval
| where cv < 0.3 AND count > 20
Phase 5: API Call Monitoring
Step 5.1 - Critical API Sequences
Monitor for this specific API call chain:
CreateProcessW / CreateProcessA with CREATE_SUSPENDED (0x00000004)
NtUnmapViewOfSection / ZwUnmapViewOfSection
VirtualAllocEx with PAGE_EXECUTE_READWRITE
WriteProcessMemory
SetThreadContext / NtSetContextThread
ResumeThread / NtResumeThread
Step 5.2 - ETW Process Hollowing Detection
# Monitor for suspicious API patterns via ETW
# Requires elevated privileges
$session = New-EtwTraceSession -Name "ProcessHollowHunt"
Add-EtwTraceProvider -SessionName "ProcessHollowHunt" `
-Guid "{22FB2CD6-0E7B-422B-A0C7-2FAD1FD0E716}" `
-Level 5
Back to mukul975/Anthropic-Cybersecurity-Skills (817 security skills) or Agent skills.