[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fWdTesiQ66ibA3cCS0fHpEWyQt-r5_RO0ESeoan9Ok9g":3},{"id":4,"question":5,"answer":6,"answerHtml":7,"slug":8,"keywords":9,"article":10,"status":34,"aiModel":39,"aiConfidence":39,"updatedAt":51,"createdAt":51,"_status":50},870,"How can Process Doppelgänging be detected?","Detection is possible because calls to key functions like `NtCreateThreadEx` can be intercepted, and there are discrepancies between process memory and the original PE file on disk. Antivirus software may also scan during transaction creation. The article notes that it cannot bypass all security products, and these differences can be used for forensic analysis. Refer to the detection section in the [Introduction to Process Doppelganging Exploitation](\u002Fnews\u002Fintroduction-to-process-doppelganging-exploitation) for more details.","\u003Cp>Detection is possible because calls to key functions like `NtCreateThreadEx` can be intercepted, and there are discrepancies between process memory and the original PE file on disk. Antivirus software may also scan during transaction creation. The article notes that it cannot bypass all security products, and these differences can be used for forensic analysis. Refer to the detection section in the [Introduction to Process Doppelganging Exploitation](\u002Fnews\u002Fintroduction-to-process-doppelganging-exploitation) for more details.\u003C\u002Fp>\u003Cp>\u003Ca href=\"\u002Fnews\u002Fintroduction-to-process-doppelganging-exploitation\">Read the related One Day Sec article\u003C\u002Fa>\u003C\u002Fp>","how-can-process-doppelganging-be-detected-1777481678685","detection, NtCreateThreadEx, memory vs PE file, antivirus bypass",{"id":11,"title":12,"slug":13,"description":14,"content":15,"contentHtml":30,"cover":31,"author":32,"views":19,"readingTime":33,"status":34,"publishedAt":35,"seo":36,"tags":41,"qaPairs":42,"meta":47,"updatedAt":48,"createdAt":49,"_status":50},212,"Introduction to Process Doppelganging Exploitation","introduction-to-process-doppelganging-exploitation","Learn about Process Doppelganging, a Windows code injection technique that bypasses security products. Includes POC testing, exploitation steps, and defense tips.",{"root":16},{"type":17,"format":18,"indent":19,"version":20,"children":21,"direction":29},"root","",0,1,[22],{"type":23,"format":18,"indent":19,"version":20,"children":24,"direction":29},"paragraph",[25],{"mode":26,"text":27,"type":28,"style":18,"detail":19,"format":19,"version":20},"normal","\u003Chtml>\u003Chead>\u003C\u002Fhead>\u003Cbody>\u003Ch2>0x00 Preface\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>At the recent BlackHat Europe 2017, Tal Liberman and Eugene Kogan introduced a new code injection technique—Process Doppelgänging\u003C\u002Fp>\u003Cp>It is said that this exploitation method supports all Windows systems and can bypass detection by most security products\u003C\u002Fp>\u003Cp>Therefore, this article will develop a program based on open-source code to implement Process Doppelgänging, test its functionality, and analyze the exploitation approach\u003C\u002Fp>\u003Cp>Reference:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fwww.blackhat.com\u002Fdocs\u002Feu-17\u002Fmaterials\u002Feu-17-Liberman-Lost-In-Transaction-Process-Doppelganging.pdf\u003C\u002Fp>\u003Ch2>0x01 Introduction\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>This article will cover the following:\u003C\u002Fp>\u003Cul>\u003Cli>Principles\u003C\u002Fli>\u003Cli>Open-source code\u003C\u002Fli>\u003Cli>Mitigation methods\u003C\u002Fli>\u003Cli>Practical testing\u003C\u002Fli>\u003Cli>Exploitation Approach\u003C\u002Fli>\u003Cli>Defense and Detection\u003C\u002Fli>\u003C\u002Ful>\u003Ch2>0x02 Process Doppelgänging Principle\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>Similar in principle to Process Hollowing, but more advanced:\u003C\u002Fp>\u003Cul>\u003Cli>No need to use a puppet process\u003C\u002Fli>\u003Cli>No special memory operations required, such as SuspendProcess and NtUnmapViewOfSection\u003C\u002Fli>\u003C\u002Ful>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>For an introduction to Process Hollowing, refer to the previous article 'Implementation and Detection of Puppet Processes'\u003C\u002Fp>\u003Ch3>Implementation Approach:\u003C\u002Fh3>\u003Ch4>1. Open a normal file and create a transaction\u003C\u002Fh4>\u003Cp>Regarding NTFS transactions, refer to:\u003C\u002Fp>\u003Cp>http:\u002F\u002Fwww.ntfs.com\u002Ftransaction.htm\u003C\u002Fp>\u003Ch4>2. Fill the transaction with payload, which is launched as a process\u003C\u002Fh4>\u003Cp>So far, antivirus software cannot scan the filled payload\u003C\u002Fp>\u003Ch4>3. Rollback transaction\u003C\u002Fh4>\u003Cp>Equivalent to reverting the transaction and cleaning up traces\u003C\u002Fp>\u003Ch3>Corresponding program implementation process:\u003C\u002Fh3>\u003Ch4>1. Create transaction\u003C\u002Fh4>\u003Cp>Key functions:\u003C\u002Fp>\u003Cul>\u003Cli>NtCreateTransaction\u003C\u002Fli>\u003C\u002Ful>\u003Ch4>2. Fill payload within this transaction\u003C\u002Fh4>\u003Cp>Key functions:\u003C\u002Fp>\u003Cul>\u003Cli>CreateFileTransacted\u003C\u002Fli>\u003Cli>NtCreateSection\u003C\u002Fli>\u003C\u002Ful>\u003Ch4>3. Launch payload as a process\u003C\u002Fh4>\u003Cp>Key functions:\u003C\u002Fp>\u003Cul>\u003Cli>NtCreateProcessEx\u003C\u002Fli>\u003Cli>NtCreateThreadEx\u003C\u002Fli>\u003C\u002Ful>\u003Ch4>4. Rollback transaction\u003C\u002Fh4>\u003Cp>Key Functions:\u003C\u002Fp>\u003Cul>\u003Cli>NtRollbackTransaction\u003C\u002Fli>\u003C\u002Ful>\u003Cp>Of course, it also involves payload writing, memory allocation, PE file structure, etc., which will not be introduced here for now. You can directly refer to the POC source code.\u003C\u002Fp>\u003Cp>For the usage of Native API, you can refer to the previous articles \"Penetration Techniques - Creation of 'Hidden' Registry\" and \"Penetration Techniques - More Tests on 'Hidden' Registry\".\u003C\u002Fp>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>For Windows 10 systems before Win10 RS3, using this method will cause a blue screen. The reason lies in the null pointer passed to the NtCreateProcessEx function. For details, refer to:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fbugs.chromium.org\u002Fp\u002Fproject-zero\u002Fissues\u002Fdetail?id=852\u003C\u002Fp>\u003Ch2>0x03 Open Source POC\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>Currently, there are two publicly available POCs\u003C\u002Fp>\u003Ch3>1. processrefund\u003C\u002Fh3>\u003Cp>Address:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fgithub.com\u002FSpajed\u002Fprocessrefund\u003C\u002Fp>\u003Cp>Currently only supports 64-bit Windows systems\u003C\u002Fp>\u003Cp>Compilation tool: VS2015, install SDK\u003C\u002Fp>\u003Cp>\u003Cstrong>Actual test:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Win7 x64\u003C\u002Fp>\u003Cp>Test as shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770017266165_0_150eb1c8fa.jpeg\">\u003C\u002Fp>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>If calc.exe under system32 is selected, insufficient permissions will be prompted\u003C\u002Fp>\u003Cp>Start process calc.exe, but actually execute MalExe.exe, pop-up dialog box\u003C\u002Fp>\u003Cp>The icon and description of process calc.exe are both normal calc.exe, digital signature is also normal, as shown below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770017290261_1_ecde4524e0.jpeg\">\u003C\u002Fp>\u003Ch3>2. POC by hfiref0x\u003C\u002Fh3>\u003Cp>https:\u002F\u002Fgist.github.com\u002Fhfiref0x\u002Fa9911a0b70b473281c9da5daea9a177f\u003C\u002Fp>\u003Cp>Only one c file, missing header file ntos.h\u003C\u002Fp>\u003Cp>Reference location:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fgithub.com\u002Fhfiref0x\u002FUACME\u002Fblob\u002Fmaster\u002FSource\u002FShared\u002Fntos.h\u003C\u002Fp>\u003Cp>But secondary modifications are still required\u003C\u002Fp>\u003Cp>To better understand the details, decided not to use the ntdll.lib file (included after installing DDK), and instead obtain Native API through ntdll (of course, the code volume will also increase)\u003C\u002Fp>\u003Cp>Rewrite an ntos.h in my own way, and modify the original POC's inject.c\u003C\u002Fp>\u003Cp>Open source address is as follows:\u003C\u002Fp>\u003Cp>An open source project\u003C\u002Fp>\u003Cp>Compilation tool: VS2012\u003C\u002Fp>\u003Cp>Supports 32-bit Windows systems\u003C\u002Fp>\u003Cp>\u003Cstrong>Actual testing:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Win7 x86\u003C\u002Fp>\u003Cp>Test as shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770017321227_2_051b4aa8d4.jpeg\">\u003C\u002Fp>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>If you choose calc.exe under system32, it will prompt insufficient permissions\u003C\u002Fp>\u003Cp>In summary, we can see that Process Doppelgänging is similar to Process Hollowing in terms of exploitation effect: launching a normal process (normal icon, signature, description) and executing payload within this process\u003C\u002Fp>\u003Cp>A disadvantage of Process Doppelgänging in exploitation: it requires file replacement, so when replacing files under system32, it will prompt insufficient permissions (administrator privileges cannot modify files in this path)\u003C\u002Fp>\u003Ch2>0x04 Exploitation Approach\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>In the previous section, we tested two POCs and gained some understanding of Process Doppelgänging.\u003C\u002Fp>\u003Cp>In practical exploitation, further modifications to the POC are required. The exploitation approach is as follows:\u003C\u002Fp>\u003Cp>Remove the functionality of reading the payload and replace it with storing the payload in a Buffer (which can be compressed and encoded to reduce its length).\u003C\u002Fp>\u003Cp>During execution, read the Buffer, decrypt it, and execute it.\u003C\u002Fp>\u003Cp>This further conceals the payload, achieving a \"fileless\" payload (the payload is stored in the exploit and does not need to be written to the hard disk).\u003C\u002Fp>\u003Ch2>0x05 Detection\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>Process Doppelgänging cannot bypass all antivirus software. Calls to several key functions (such as NtCreateThreadEx) can still be intercepted, and there are differences between the process memory and the PE file.\u003C\u002Fp>\u003Ch2>0x06 Summary\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>This article introduced the principles of Process Doppelgänging. Based on open-source code, a program was developed to achieve exploitation on Windows x86 and x64 systems, test its functionality, analyze the exploitation approach, and introduce detection methods.\u003C\u002Fp>\u003C\u002Fbody>\u003C\u002Fhtml>","text","ltr","\u003Chtml>\u003Chead>\u003C\u002Fhead>\u003Cbody>\u003Ch2>0x00 Preface\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>At the recent BlackHat Europe 2017, Tal Liberman and Eugene Kogan introduced a new code injection technique—Process Doppelgänging\u003C\u002Fp>\u003Cp>It is said that this exploitation method supports all Windows systems and can bypass detection by most security products\u003C\u002Fp>\u003Cp>Therefore, this article will develop a program based on open-source code to implement Process Doppelgänging, test its functionality, and analyze the exploitation approach\u003C\u002Fp>\u003Cp>Reference:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fwww.blackhat.com\u002Fdocs\u002Feu-17\u002Fmaterials\u002Feu-17-Liberman-Lost-In-Transaction-Process-Doppelganging.pdf\u003C\u002Fp>\u003Ch2>0x01 Introduction\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>This article will cover the following:\u003C\u002Fp>\u003Cul>\u003Cli>Principles\u003C\u002Fli>\u003Cli>Open-source code\u003C\u002Fli>\u003Cli>Mitigation methods\u003C\u002Fli>\u003Cli>Practical testing\u003C\u002Fli>\u003Cli>Exploitation Approach\u003C\u002Fli>\u003Cli>Defense and Detection\u003C\u002Fli>\u003C\u002Ful>\u003Ch2>0x02 Process Doppelgänging Principle\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>Similar in principle to Process Hollowing, but more advanced:\u003C\u002Fp>\u003Cul>\u003Cli>No need to use a puppet process\u003C\u002Fli>\u003Cli>No special memory operations required, such as SuspendProcess and NtUnmapViewOfSection\u003C\u002Fli>\u003C\u002Ful>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>For an introduction to Process Hollowing, refer to the previous article 'Implementation and Detection of Puppet Processes'\u003C\u002Fp>\u003Ch3>Implementation Approach:\u003C\u002Fh3>\u003Ch4>1. Open a normal file and create a transaction\u003C\u002Fh4>\u003Cp>Regarding NTFS transactions, refer to:\u003C\u002Fp>\u003Cp>http:\u002F\u002Fwww.ntfs.com\u002Ftransaction.htm\u003C\u002Fp>\u003Ch4>2. Fill the transaction with payload, which is launched as a process\u003C\u002Fh4>\u003Cp>So far, antivirus software cannot scan the filled payload\u003C\u002Fp>\u003Ch4>3. Rollback transaction\u003C\u002Fh4>\u003Cp>Equivalent to reverting the transaction and cleaning up traces\u003C\u002Fp>\u003Ch3>Corresponding program implementation process:\u003C\u002Fh3>\u003Ch4>1. Create transaction\u003C\u002Fh4>\u003Cp>Key functions:\u003C\u002Fp>\u003Cul>\u003Cli>NtCreateTransaction\u003C\u002Fli>\u003C\u002Ful>\u003Ch4>2. Fill payload within this transaction\u003C\u002Fh4>\u003Cp>Key functions:\u003C\u002Fp>\u003Cul>\u003Cli>CreateFileTransacted\u003C\u002Fli>\u003Cli>NtCreateSection\u003C\u002Fli>\u003C\u002Ful>\u003Ch4>3. Launch payload as a process\u003C\u002Fh4>\u003Cp>Key functions:\u003C\u002Fp>\u003Cul>\u003Cli>NtCreateProcessEx\u003C\u002Fli>\u003Cli>NtCreateThreadEx\u003C\u002Fli>\u003C\u002Ful>\u003Ch4>4. Rollback transaction\u003C\u002Fh4>\u003Cp>Key Functions:\u003C\u002Fp>\u003Cul>\u003Cli>NtRollbackTransaction\u003C\u002Fli>\u003C\u002Ful>\u003Cp>Of course, it also involves payload writing, memory allocation, PE file structure, etc., which will not be introduced here for now. You can directly refer to the POC source code.\u003C\u002Fp>\u003Cp>For the usage of Native API, you can refer to the previous articles \"Penetration Techniques - Creation of 'Hidden' Registry\" and \"Penetration Techniques - More Tests on 'Hidden' Registry\".\u003C\u002Fp>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>For Windows 10 systems before Win10 RS3, using this method will cause a blue screen. The reason lies in the null pointer passed to the NtCreateProcessEx function. For details, refer to:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fbugs.chromium.org\u002Fp\u002Fproject-zero\u002Fissues\u002Fdetail?id=852\u003C\u002Fp>\u003Ch2>0x03 Open Source POC\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>Currently, there are two publicly available POCs\u003C\u002Fp>\u003Ch3>1. processrefund\u003C\u002Fh3>\u003Cp>Address:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fgithub.com\u002FSpajed\u002Fprocessrefund\u003C\u002Fp>\u003Cp>Currently only supports 64-bit Windows systems\u003C\u002Fp>\u003Cp>Compilation tool: VS2015, install SDK\u003C\u002Fp>\u003Cp>\u003Cstrong>Actual test:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Win7 x64\u003C\u002Fp>\u003Cp>Test as shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770017266165_0_150eb1c8fa-1.jpeg\">\u003C\u002Fp>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>If calc.exe under system32 is selected, insufficient permissions will be prompted\u003C\u002Fp>\u003Cp>Start process calc.exe, but actually execute MalExe.exe, pop-up dialog box\u003C\u002Fp>\u003Cp>The icon and description of process calc.exe are both normal calc.exe, digital signature is also normal, as shown below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770017290261_1_ecde4524e0-1.jpeg\">\u003C\u002Fp>\u003Ch3>2. POC by hfiref0x\u003C\u002Fh3>\u003Cp>https:\u002F\u002Fgist.github.com\u002Fhfiref0x\u002Fa9911a0b70b473281c9da5daea9a177f\u003C\u002Fp>\u003Cp>Only one c file, missing header file ntos.h\u003C\u002Fp>\u003Cp>Reference location:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fgithub.com\u002Fhfiref0x\u002FUACME\u002Fblob\u002Fmaster\u002FSource\u002FShared\u002Fntos.h\u003C\u002Fp>\u003Cp>But secondary modifications are still required\u003C\u002Fp>\u003Cp>To better understand the details, decided not to use the ntdll.lib file (included after installing DDK), and instead obtain Native API through ntdll (of course, the code volume will also increase)\u003C\u002Fp>\u003Cp>Rewrite an ntos.h in my own way, and modify the original POC's inject.c\u003C\u002Fp>\u003Cp>Open source address is as follows:\u003C\u002Fp>\u003Cp>An open source project\u003C\u002Fp>\u003Cp>Compilation tool: VS2012\u003C\u002Fp>\u003Cp>Supports 32-bit Windows systems\u003C\u002Fp>\u003Cp>\u003Cstrong>Actual testing:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Win7 x86\u003C\u002Fp>\u003Cp>Test as shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770017321227_2_051b4aa8d4-1.jpeg\">\u003C\u002Fp>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>If you choose calc.exe under system32, it will prompt insufficient permissions\u003C\u002Fp>\u003Cp>In summary, we can see that Process Doppelgänging is similar to Process Hollowing in terms of exploitation effect: launching a normal process (normal icon, signature, description) and executing payload within this process\u003C\u002Fp>\u003Cp>A disadvantage of Process Doppelgänging in exploitation: it requires file replacement, so when replacing files under system32, it will prompt insufficient permissions (administrator privileges cannot modify files in this path)\u003C\u002Fp>\u003Ch2>0x04 Exploitation Approach\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>In the previous section, we tested two POCs and gained some understanding of Process Doppelgänging.\u003C\u002Fp>\u003Cp>In practical exploitation, further modifications to the POC are required. The exploitation approach is as follows:\u003C\u002Fp>\u003Cp>Remove the functionality of reading the payload and replace it with storing the payload in a Buffer (which can be compressed and encoded to reduce its length).\u003C\u002Fp>\u003Cp>During execution, read the Buffer, decrypt it, and execute it.\u003C\u002Fp>\u003Cp>This further conceals the payload, achieving a \"fileless\" payload (the payload is stored in the exploit and does not need to be written to the hard disk).\u003C\u002Fp>\u003Ch2>0x05 Detection\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>Process Doppelgänging cannot bypass all antivirus software. Calls to several key functions (such as NtCreateThreadEx) can still be intercepted, and there are differences between the process memory and the PE file.\u003C\u002Fp>\u003Ch2>0x06 Summary\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>This article introduced the principles of Process Doppelgänging. Based on open-source code, a program was developed to achieve exploitation on Windows x86 and x64 systems, test its functionality, analyze the exploitation approach, and introduce detection methods.\u003C\u002Fp>\u003C\u002Fbody>\u003C\u002Fhtml>",721,"Onedaysec",4,"published","2026-02-02T07:38:21.197Z",{"title":37,"description":14,"keywords":38,"ogImage":39,"canonicalUrl":39,"noIndex":40},"Process Doppelganging Exploitation: Bypass Security & Code Injection","Process Doppelganging, code injection, Windows exploitation, security bypass, antivirus evasion, NTFS transactions, POC, malware, penetration testing",null,false,[],{"docs":43,"hasNextPage":40},[4,44,45,46],869,868,867,{"title":39,"description":39,"image":39},"2026-07-24T15:37:11.114Z","2026-07-23T16:02:12.917Z","draft","2026-07-23T16:15:14.747Z"]