MITRE ATT&CK technique

T1093

Process Hollowing

Process hollowing occurs when a process is created in a suspended state then its memory is unmapped and replaced with malicious code. Similar to [Process Injection](https://attack.mitre.org/techniques/T1055), execution of the malicious code is masked under a legitimate process and may evade defenses and detection analysis. (Citation: Leitch Hollowing) (Citation: Elastic Process Injection July 2017)

TA0005

Linked Daily items

0 hits
No Daily items mapped yet.

Linked Incidents

0 hits
No incidents mapped yet.

Predicted CVE associations

0 items
No mappings yet for this technique.

These relationships come from the current triage artifact and are not official MITRE mappings.