Official Description

Adversaries may inject code into processes in order to evade process-based defenses as well as possibly elevate privileges. Process injection is a method of executing arbitrary code in the address space of a separate live process. Running code in the context of another process may allow access to the process's memory, system/network resources, and possibly elevated privileges. Execution via process injection may also evade detection from security products since the execution is masked under a legitimate process.

There are many different ways to inject code into a process, many of which abuse legitimate functionalities. These implementations exist for every major OS but are typically platform specific.

More sophisticated samples may perform multiple process injections to segment modules and further evade detection, utilizing named pipes or other inter-process communication (IPC) mechanisms as a communication channel.
Tactics
Stealth, Privilege Escalation
Platforms
Linux, macOS, Windows
MITRE Version
2.0
Last Modified
May 12, 2026

View on MITRE ATT&CK ↗

Sub-techniques (12)

VIEW MORE

Reported Context (5)

CVE (1)

Malware (9)

Threat Actors (5)

MITRE ATT&CK (32)

VIEW MORE

Vendors (9)

Products (24)

VIEW MORE

Tools (7)

Industries (1)

Countries (2)

Note: Related entities, including threat actors, malware, CVEs, MITRE ATT&CK techniques, vendors, products, tools, countries, and industries, are shown when they appear in the same reporting. Their presence does not necessarily mean they were targeted, compromised, vulnerable, responsible for the activity, or directly involved in the incident.