title: Potential Process Hollowing Activity id: c4b890e5-8d8c-4496-8c66-c805753817cd status: test description: Detects when a memory process image does not match the disk image, indicative of process hollowing. references: - https://twitter.com/SecurePeacock/status/1486054048390332423?s=20 - https://www.bleepingcomputer.com/news/microsoft/microsoft-sysmon-now-detects-malware-process-tampering-attempts/ author: Christopher Peacock '@securepeacock', SCYTHE '@scythe_io', Sittikorn S date: 2022-01-25 modified: 2023-11-28 tags: - attack.privilege-escalation - attack.stealth - attack.t1055.012 logsource: product: windows category: process_tampering detection: selection: Type: 'Image is replaced' filter_main_generic: Image|contains: - ':\Program Files (x86)' - ':\Program Files\' - ':\Windows\System32\wbem\WMIADAP.exe' - ':\Windows\SysWOW64\wbem\WMIADAP.exe' filter_optional_opera: Image|contains: '\AppData\Local\Programs\Opera\' Image|endswith: '\opera.exe' filter_optional_edge: Image|endswith: '\WindowsApps\MicrosoftEdge.exe' condition: selection and not 1 of filter_main_* and not 1 of filter_optional_* falsepositives: - Unknown level: medium