A newly documented Windows injection approach, dubbed Process Parameter Poisoning or P³, uses process startup parameters as an unconventional staging area for shellcode. Implemented in the P³-Shellcode Loader proof of concept, the technique can reduce exposure to telemetry that endpoint…
The post Process Parameter Poisoning Technique Hides Shellcode Inside Windows Startup Data appeared first on IT Security News.