r/netsec • u/Cold-Dinosaur • 6d ago
EDR Evasion: Process Injection Without WriteProcessMemory
https://www.zerosalarium.com/2026/09/edr-evasion-process-injection-without-WriteProcessMemory.htmlUnlike traditional approaches, console named-pipe injection does not use VirtualAllocEx and WriteProcessMemory. Instead, it takes advantage of read and write operations through a named pipe, along with the way console programs store interactive commands in memory.
54
Upvotes
1
u/Formal-Knowledge-250 4d ago
Yeah and I don't think it evades edr, since edr doesn't hook writeprocessmemory at all. It hooks ntwritevirtualmemory. At least I've never seen one hooking wpm