{"id":"T1055.002","name":"Portable Executable Injection","url":"https://attack.mitre.org/techniques/T1055/002","tactics":["stealth","privilege-escalation"],"platforms":["Windows"],"live":true,"revoked":false,"deprecated":false,"revoked_by":null,"detection_strategies":[{"id":"DET0106","stix_id":"x-mitre-detection-strategy--65c18137-cad3-4fd3-8b24-22a61850c8a1","name":"Behavioral Detection of PE Injection via Remote Memory Mapping","url":"https://attack.mitre.org/detectionstrategies/DET0106","analytics":[{"id":"AN0297","stix_id":"x-mitre-analytic--d845dc30-6950-4f0c-9342-29b7a7315bd2","name":"Analytic 0297","description":"Detects PE injection through a behavioral sequence where one process opens (OpenProcess) a handle to another, allocates remote memory (VirtualAllocEx), writes a PE header (MZ) or shellcode (WriteProcessMemory), then initiates a new thread (CreateRemoteThread or NtCreateThreadEx) in that process—executing injected code in memory without touching disk. Optional: injects a trampoline or shellcode that unpacks/reflectively maps the payload.","url":"https://attack.mitre.org/detectionstrategies/DET0106#AN0297","platforms":["Windows"],"log_source_references":[{"name":"WinEventLog:Sysmon","channel":"EventCode=10","data_component":"DC0035","data_component_name":"Process Access","log_source_slug":"wineventlog-sysmon"},{"name":"WinEventLog:Sysmon","channel":"EventCode=8","data_component":"DC0020","data_component_name":"Process Modification","log_source_slug":"wineventlog-sysmon"},{"name":"WinEventLog:Sysmon","channel":"EventCode=1","data_component":"DC0032","data_component_name":"Process Creation","log_source_slug":"wineventlog-sysmon"},{"name":"WinEventLog:Sysmon","channel":"EventCode=11","data_component":"DC0039","data_component_name":"File Creation","log_source_slug":"wineventlog-sysmon"}],"mutable_elements":[{"field":"PayloadEntropyThreshold","description":"Controls for detecting high-entropy memory writes indicating shellcode or encrypted PE"},{"field":"TargetProcessList","description":"High-value or sensitive processes that should never have remote threads injected"},{"field":"TimeWindow","description":"Max allowed delay between memory write and thread execution"},{"field":"ParentProcessAnomalyThreshold","description":"Used to filter legitimate process hierarchies vs anomalous injection sources"}],"live":true,"detection_strategies":["DET0106"],"techniques":["T1055.002"]}],"live":true,"version":"1.0","techniques":["T1055.002"]}],"sigma_rules":[],"kev_cves":[],"_built":"2026-08-23 05:47 UTC","_attack_version":"19.2","_sigma_commit":"da9bb07d642a2826e89702445d32c795209ec108"}