{"id":"T1055.011","name":"Extra Window Memory Injection","url":"https://attack.mitre.org/techniques/T1055/011","tactics":["stealth","privilege-escalation"],"platforms":["Windows"],"live":true,"revoked":false,"deprecated":false,"revoked_by":null,"detection_strategies":[{"id":"DET0217","stix_id":"x-mitre-detection-strategy--1a8d87f1-48ca-4929-a5cc-2b2a03983f12","name":"Detection Strategy for Extra Window Memory (EWM) Injection on Windows","url":"https://attack.mitre.org/detectionstrategies/DET0217","analytics":[{"id":"AN0608","stix_id":"x-mitre-analytic--6ec034ac-289d-48d1-b310-021dfbf7087b","name":"Analytic 0608","description":"Detects adversary manipulation of Extra Window Memory (EWM) in a GUI process, where the attacker uses SetWindowLong or SetClassLong to redirect function pointers to injected shellcode stored in shared memory, then triggers execution via a window message like SendNotifyMessage.","url":"https://attack.mitre.org/detectionstrategies/DET0217#AN0608","platforms":["Windows"],"log_source_references":[{"name":"WinEventLog:Sysmon","channel":"EventCode=10","data_component":"DC0035","data_component_name":"Process Access","log_source_slug":"wineventlog-sysmon"},{"name":"etw:Microsoft-Windows-Win32k","channel":"SetWindowLong, SetClassLong, NtUserMessageCall, SendNotifyMessage, PostMessage","data_component":"DC0021","data_component_name":"OS API Execution","log_source_slug":"etw-microsoft-windows-win32k"},{"name":"WinEventLog:Security","channel":"EventCode=4688","data_component":"DC0032","data_component_name":"Process Creation","log_source_slug":"wineventlog-security"}],"mutable_elements":[{"field":"TargetWindowClassRegex","description":"Regex to scope suspicious or uncommon GUI class names registered by user-created processes"},{"field":"ExecutionTriggerWindowMessage","description":"API calls like SendNotifyMessage or PostMessage that deliver execution to the shellcode location"},{"field":"SharedSectionWriteThreshold","description":"Set byte count thresholds on suspicious memory writes to known shared sections"},{"field":"TimeWindowSetWindowLongToMessageTrigger","description":"Define max time (e.g., <10s) between API call to set window memory and the message call to trigger it"}],"live":true,"detection_strategies":["DET0217"],"techniques":["T1055.011"]}],"live":true,"version":"1.0","techniques":["T1055.011"]}],"sigma_rules":[{"id":"a24e5861-c6ca-4fde-a93c-ba9256feddf0","title":"Uncommon Process Access Rights For Target Image","author":"Nasreddine Bencherchali (Nextron Systems), frack113","status":"test","level":"low","date":"2024-05-27","modified":null,"description":"Detects process access request to uncommon target images with a \"PROCESS_ALL_ACCESS\" access mask.\n","references":["https://learn.microsoft.com/en-us/windows/win32/procthread/process-security-and-access-rights"],"logsource":{"product":"windows","category":"process_access"},"tags":["attack.privilege-escalation","attack.stealth","attack.t1055.011"],"path":"rules/windows/process_access/proc_access_win_susp_all_access_uncommon_target.yml","techniques":["T1055.011"],"cves":[]}],"kev_cves":[],"_built":"2026-08-23 05:47 UTC","_attack_version":"19.2","_sigma_commit":"da9bb07d642a2826e89702445d32c795209ec108"}