Researchers disclosed Process Parameter Poisoning, a Windows process-injection technique that stores shellcode in process-initialization parameters propagated to a newly created process's Process Environment Block (PEB). Rather than relying on heavily monitored cross-process memory functions such as WriteProcessMemory and VirtualAllocEx, the technique uses those parameter buffers and thread-execution hijacking to run the payload.
Flashpoint validated the method with a Rust proof of concept in a laboratory environment and reported no alerts from tested EDR/XDR products when additional evasion measures were applied. The researchers stressed that this is not evidence of in-the-wild exploitation; defenders should monitor for anomalous or high-entropy process parameters, manipulated thread contexts, execution originating from PEB parameter buffers, and memory-protection changes that render such regions executable.

Get the actors, campaigns, and ATT&CK mapping behind it.
1 event from the most recent confirmed update back to the earliest known activity.
Researchers Max Hirschberger and Ogulcan Ugur disclosed Process Parameter Poisoning, a Windows process-injection and EDR-evasion technique that stores payloads in process-initialization data and uses thread execution hijacking. Flashpoint validated the technique with a Rust proof of concept in laboratory testing, reporting no alerts after combining it with additional evasion measures.
Get the adversaries, campaigns, and ATT&CK mapping behind this technique, with detections ready to deploy.
3 references tracked. Mallory keeps watching after this page renders.
flashpoint.io
Open sourcelearn.microsoft.com
Open sourcelearn.microsoft.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.