A groundbreaking Windows process injection method, revealed by security researcher Two Seven One Three, circumvents traditional detection systems by avoiding commonly monitored APIs such as VirtualAllocEx and WriteProcessMemory. This innovative technique, called console named-pipe injection, introduces payloads via a redirected standard input of a child console process, utilizing existing memory allocations. This method disrupts standard detection patterns that rely on identifying the allocate-write-execute sequence typical in process injection attacks.

Process injection involves embedding arbitrary code within another process, potentially camouflaging malicious activity within legitimate applications. The MITRE ATT&CK framework identifies this behavior as T1055. Traditional methods open or create a target process, allocate remote memory, copy code using WriteProcessMemory, and manipulate threads. EDR solutions typically monitor this sequence of actions through memory and thread signaling.

This novel approach leverages Windows interprocess communication. The injector creates an interactive console child, such as nslookup.exe or netsh.exe, redirects its standard input to a pipe, and sends the payload using WriteFile. The information resides in the console program’s address space as it processes input. A proof of concept searches for a distinctive marker in memory, then calculates the shellcode entry point.

The injector uses VirtualProtectEx to make the existing memory executable, suspends a thread, adjusts its instruction pointer, and resumes it. Microsoft notes that VirtualProtectEx changes protections in another process and recommends suspending a thread before modifying its context. Demonstrations show that nslookup.exe regions have their protection status altered to executable-read-write, with the main thread redirected.

To avoid detection, payloads need to circumvent bytes like carriage return and line feed, as these could be misinterpreted by console parsing. While related research bypassed EDR products, this technique requires defenders to go beyond monitoring single APIs. Detection should focus on unusual parent-child process relationships, redirected handles, memory scanning, and the use of VirtualProtectEx.

Sysmon EventIDs 17 and 18 can provide telemetry for named-pipe interactions, though richer endpoint visibility is necessary for anonymous pipes. Security teams should establish baselines for console automation and investigate rare process combinations instead of flagging all related activities. This research emphasizes the importance of comprehensive detection strategies that assess process creation, handle sharing, memory protection, and control flow changes.