Pergunta de entrevista da empresa Sophos

Q: Describe process injection and how to detect it.

Resposta da entrevista

Sigiloso

17 de jul. de 2024

A: You will generally be OpenProcess, Allocation of Virtual Memory, writing a payload to that memory then creating threads to execute that payload. There's several methods, and generally you watch those system calls to detect them.