Microsoft and Elastic published technical details on Process Ghosting and related Windows executable image tampering techniques that let malware run after its backing file has been altered or deleted, bypassing antimalware scanning during a time-of-check/time-of-use gap in process creation. The technique abuses legacy process creation behavior, including use of the NtCreateProcessEx path, and is closely related to process doppelganging, process herpaderping, and process reimaging. Elastic described how an attacker can create a file, mark it delete-pending, write a payload, map it into an image section, close the handle so the file is removed, and then launch a process from the now fileless image section.
Elastic reported that a proof-of-concept showed Windows Defender failing to scan a payload because the file was already delete-pending or deleted when scanning occurred, and said it had reported the issue to Microsoft’s MSRC, which replied that it did not meet the servicing bar. Microsoft later described a detection approach in Microsoft Defender for Endpoint that identifies processes created without the GUID_ECP_CREATE_USER_PROCESS extra create parameter and checks whether the executable image section lost disk coherency and became page-file-backed via MmDoesFileHaveUserWritableReferences. According to Microsoft, combining those signals enables detection of known and previously unpublished variants and can generate alerts for ghosting, herpaderping, and doppelganging seen in the wild.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
4 events from the most recent confirmed update back to the earliest known activity.
Microsoft disclosed a new Microsoft Defender for Endpoint detection method for stealthy Windows process execution techniques that abuse legacy NtCreateProcessEx behavior, including process ghosting, herpaderping, and doppelganging. The approach uses absence of the GUID_ECP_CREATE_USER_PROCESS signal plus image-section coherency checks to identify these attacks and generate alerts seen in the wild.
Gabriel Landau published a blog post describing Process Ghosting as a new Windows executable image tampering attack that runs malware from an image section after the backing file is deleted. The post also showed Windows Defender failing to scan and block a payload when the file was delete-pending or already deleted.
Microsoft responded to Elastic's MSRC report and said the issue did not meet its servicing bar. The Elastic blog dates that response to 2021-05-10.
Elastic Security Labs submitted a report about the Process Ghosting issue to the Microsoft Security Response Center. The blog states this occurred on 2021-05-06.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
3 references tracked. Mallory keeps watching after this page renders.
elastic.co
Open sourcemicrosoft.com
Open sourcedocs.microsoft.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.