[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fYwuD-krTLcWvs3mvrqDgFMAkyc6HirQMAXD0DiUVdU0":3},{"id":4,"question":5,"answer":6,"answerHtml":7,"slug":8,"keywords":9,"article":10,"status":34,"aiModel":39,"aiConfidence":39,"updatedAt":51,"createdAt":51,"_status":50},1063,"What tools did Casey Smith share to execute APC injection and avoid Sysmon?","Casey Smith shared C# implementations that leverage `QueueUserAPC` for shellcode injection, designed to run under `InstallUtil.exe` and `Msbuild.exe`. These utilities are trusted by Windows and often allowed through application whitelisting solutions. The code, available on GitHub, executes the injection without creating a remote thread, thus bypassing Sysmon's CreateRemoteThread monitoring, similar to [Testing and Analysis of Bypassing AppLocker Using LUA Scripts](\u002Fnews\u002Ftesting-and-analysis-of-bypassing-applocker-using-lua-scripts).","\u003Cp>Casey Smith shared C# implementations that leverage `QueueUserAPC` for shellcode injection, designed to run under `InstallUtil.exe` and `Msbuild.exe`. These utilities are trusted by Windows and often allowed through application whitelisting solutions. The code, available on GitHub, executes the injection without creating a remote thread, thus bypassing Sysmon&#39;s CreateRemoteThread monitoring, similar to [Testing and Analysis of Bypassing AppLocker Using LUA Scripts](\u002Fnews\u002Ftesting-and-analysis-of-bypassing-applocker-using-lua-scripts).\u003C\u002Fp>\u003Cp>\u003Ca href=\"\u002Fnews\u002Fdll-injection-via-apc-bypassing-sysmon-monitoring\">Read the related One Day Sec article\u003C\u002Fa>\u003C\u002Fp>","what-tools-did-casey-smith-share-to-execute-apc-injection-and-avoid-sysmon-1777480848091","Casey Smith, C#, InstallUtil.exe, Msbuild.exe, shellcode injection, QueueUserAPC",{"id":11,"title":12,"slug":13,"description":14,"content":15,"contentHtml":30,"cover":31,"author":32,"views":19,"readingTime":33,"status":34,"publishedAt":35,"seo":36,"tags":41,"qaPairs":42,"meta":47,"updatedAt":48,"createdAt":49,"_status":50},259,"DLL Injection via APC - Bypassing Sysmon Monitoring","dll-injection-via-apc-bypassing-sysmon-monitoring","Learn how to perform DLL injection via APC to bypass Sysmon monitoring of CreateRemoteThread. Includes C++ and C# implementations, Sysmon config testing, and evasion methods.",{"root":16},{"type":17,"format":18,"indent":19,"version":20,"children":21,"direction":29},"root","",0,1,[22],{"type":23,"format":18,"indent":19,"version":20,"children":24,"direction":29},"paragraph",[25],{"mode":26,"text":27,"type":28,"style":18,"detail":19,"format":19,"version":20},"normal","\u003Chtml>\u003Chead>\u003C\u002Fhead>\u003Cbody>\u003Ch2>0x00 Preface\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>To perform remote injection into a specified process, the Windows API CreateRemoteThread is typically used to create a remote thread, thereby injecting a DLL or executing shellcode.\u003C\u002Fp>\u003Cp>Sysmon can be used to monitor and log system activities, including CreateRemoteThread operations.\u003C\u002Fp>\u003Cp>CreateRemoteThread is not the only injection method; can other injection techniques bypass Sysmon monitoring?\u003C\u002Fp>\u003Cp>Casey Smith @subTee provided the answer in his article:\u003C\u002Fp>\u003Cp>Shellcode Injection via QueueUserAPC - Hiding From Sysmon\u003C\u002Fp>\u003Cp>\u003Cstrong>The address is as follows:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>http:\u002F\u002Fsubt0x10.blogspot.com\u002F2017\u002F01\u002Fshellcode-injection-via-queueuserapc.html\u003C\u002Fp>\u003Ch2>0x01 Introduction\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>This article will cover the following topics:\u003C\u002Fp>\u003Cul>\u003Cli>Sysmon configuration testing to monitor CreateRemoteThread operations\u003C\u002Fli>\u003Cli>C++ implementation of DLL injection via APC\u003C\u002Fli>\u003Cli>Bypassing Sysmon Testing\u003C\u002Fli>\u003Cli>C# implementation code and usage shared by Casey Smith@subTee\u003C\u002Fli>\u003C\u002Ful>\u003Ch3>Sysmon:\u003C\u002Fh3>\u003Cp>Can be used to monitor and record system activities, logging to Windows event logs, including the following events:\u003C\u002Fp>\u003Cul>\u003Cli>Event ID 1: Process creation\u003C\u002Fli>\u003Cli>Event ID 2: A process changed a file creation time\u003C\u002Fli>\u003Cli>Event ID 3: Network connection\u003C\u002Fli>\u003Cli>Event ID 4: Sysmon service state changed\u003C\u002Fli>\u003Cli>Event ID 5: Process terminated\u003C\u002Fli>\u003Cli>Event ID 6: Driver loaded\u003C\u002Fli>\u003Cli>Event ID 7: Image loaded\u003C\u002Fli>\u003Cli>Event ID 8: CreateRemoteThread\u003C\u002Fli>\u003Cli>Event ID 9: RawAccessRead\u003C\u002Fli>\u003Cli>Event ID 10: ProcessAccess\u003C\u002Fli>\u003Cli>Event ID 11: FileCreate\u003C\u002Fli>\u003Cli>Event ID 12: RegistryEvent (Object create and delete)\u003C\u002Fli>\u003Cli>Event ID 13: RegistryEvent (Value Set)\u003C\u002Fli>\u003Cli>Event ID 14: RegistryEvent (Key and Value Rename)\u003C\u002Fli>\u003Cli>Event ID 15: FileCreateStreamHash\u003C\u002Fli>\u003Cli>Event ID 255: Error\u003C\u002Fli>\u003C\u002Ful>\u003Cp>For details, see https:\u002F\u002Ftechnet.microsoft.com\u002Fen-us\u002Fsysinternals\u002Fsysmon\u003C\u002Fp>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>CreateRemoteThread is Event ID 8\u003C\u002Fp>\u003Ch3>DLL injection\u003C\u002Fh3>\u003Cp>Common methods:\u003C\u002Fp>\u003Cul>\u003Cli>Create a new thread\u003C\u002Fli>\u003Cli>Set thread context, modify registers\u003C\u002Fli>\u003Cli>Insert into APC queue\u003C\u002Fli>\u003Cli>Modify registry\u003C\u002Fli>\u003Cli>Hook window messages\u003C\u002Fli>\u003Cli>Remote Manual Implementation of LoadLibrary\u003C\u002Fli>\u003C\u002Ful>\u003Cp>Cited from http:\u002F\u002Fwww.cnblogs.com\u002FuAreKongqi\u002Fp\u002F6012353.html\u003C\u002Fp>\u003Ch3>Shellcode Injection via QueueUserAPC - Hiding From Sysmon:\u003C\u002Fh3>\u003Cp>C# implementation, executing shellcode by calling QueueUserAPC, applicable to InstallUtil.exe and Msbuild.exe, capable of bypassing Sysmon's monitoring of Event ID 8: CreateRemoteThread\u003C\u002Fp>\u003Cp>\u003Cstrong>Article URL:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>http:\u002F\u002Fsubt0x10.blogspot.com\u002F2017\u002F01\u002Fshellcode-injection-via-queueuserapc.html\u003C\u002Fp>\u003Ch2>0x02 Introduction to Sysmon\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>\u003Cstrong>Download URL:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>https:\u002F\u002Ftechnet.microsoft.com\u002Fen-us\u002Fsysinternals\u002Fsysmon\u003C\u002Fp>\u003Cp>Installed on the system as a system service and driver\u003C\u002Fp>\u003Cp>Used to monitor and log system activities, recording them into Windows event logs\u003C\u002Fp>\u003Cp>Provides detailed information on operations such as process creation, network connections, and file creation time changes\u003C\u002Fp>\u003Cp>Through event logs, abnormal activities can be identified to understand attackers' operations on the network\u003C\u002Fp>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>After installing Sysmon on the system, a new service named Sysmon is added\u003C\u002Fp>\u003Cp>As shown in the figure\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770015591191_0_310355993a.jpeg\">\u003C\u002Fp>\u003Cp>That is to say, if an attacker gains host privileges, they can see the installation of Sysmon by viewing the installed services\u003C\u002Fp>\u003Ch3>Installation\u003C\u002Fh3>\u003Cp>Install with default configuration:\u003C\u002Fp>\u003Cp>sysmon -accepteula –i -n\u003C\u002Fp>\u003Cp>Install with configuration file:\u003C\u002Fp>\u003Cp>sysmon -c config.xml\u003C\u002Fp>\u003Cp>Example format of the configuration file config.xml is as follows:\u003C\u002Fp>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>XML is case-sensitive\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>\u003Csysmon schemaversion=\"3.20\">      \u003Cbr>\u003C!-- Capture all hashes -->      \u003Cbr>\u003Chashalgorithms>*\u003C\u002Fhashalgorithms>      \u003Cbr>\u003Ceventfiltering>        \u003Cbr>\u003C!-- Log all drivers except if the signature -->       \u003Cbr> \u003C!-- contains Microsoft or Windows -->       \u003Cbr> \u003Cdriverload onmatch=\"exclude\">          \u003Cbr>\u003Csignature condition=\"contains\">microsoft\u003C\u002Fsignature>         \u003Cbr> \u003Csignature condition=\"contains\">windows\u003C\u002Fsignature>        \u003Cbr>\u003C\u002Fdriverload>       \u003Cbr> \u003C!-- Do not log process termination -->        \u003Cbr>\u003Cprocessterminate onmatch=\"include\">       \u003Cbr> \u003C!-- Log network connection if the destination port equal 443 -->        \u003Cbr>\u003C!-- or 80, and process isn't InternetExplorer -->        \u003Cbr>\u003Cnetworkconnect onmatch=\"include\">          \u003Cbr>\u003Cdestinationport>443\u003C\u002Fdestinationport>          \u003Cbr>\u003Cdestinationport>80\u003C\u002Fdestinationport>        \u003Cbr>\u003C\u002Fnetworkconnect>        \u003Cbr>\u003Cnetworkconnect onmatch=\"exclude\">          \u003Cbr>\u003Cimg condition=\"end with\">iexplore.exe       \u003Cbr> \u003C\u002Fnetworkconnect>     \u003Cbr> \u003C\u002Fprocessterminate>\u003C\u002Feventfiltering>    \u003Cbr>\u003C\u002Fsysmon>\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>This example is referenced from http:\u002F\u002Fwww.freebuf.com\u002Fsectool\u002F122779.html\u003C\u002Fp>\u003Ch3>View Configuration\u003C\u002Fh3>\u003Cp>sysmon -c\u003C\u002Fp>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Configuration properties are saved in the registry at the following location:\u003C\u002Fp>\u003Cp>HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\SysmonDrv\\Parameters\u003C\u002Fp>\u003Cp>As shown in the figure\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770015595997_1_da568a1d78.jpeg\">\u003C\u002Fp>\u003Ch3>View Log Records\u003C\u002Fh3>\u003Cp>1. Via the panel\u003C\u002Fp>\u003Cp>Location as follows:\u003C\u002Fp>\u003Cp>Control Panel\\System and Security-View event logs\u003C\u002Fp>\u003Cp>Applications and Services Logs-Microsoft-Windows-Sysmon-Operational\u003C\u002Fp>\u003Cp>As shown in the figure\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770015599288_2_fa2d80eb55.jpeg\">\u003C\u002Fp>\u003Cp>2. View via PowerShell, command as follows:\u003C\u002Fp>\u003Cp>(Administrator privileges)\u003C\u002Fp>\u003Cp>Get-WinEvent -FilterHashtable @{logname=\"Microsoft-Windows-Sysmon\u002FOperational\";}\u003C\u002Fp>\u003Ch3>Monitor and log CreateRemoteThread\u003C\u002Fh3>\u003Cp>Configuration file as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>\u003Csysmon schemaversion=\"3.20\">      \u003Cbr>\u003C!-- Capture all hashes -->      \u003Cbr>\u003Chashalgorithms>*\u003C\u002Fhashalgorithms>      \u003Cbr> \u003Ceventfiltering>        \u003Cbr>\u003C!-- Log all drivers except if the signature -->\u003Cbr> \u003C!-- contains Microsoft or Windows -->\u003Cbr>\u003Ccreateremotethread onmatch=\"include\">\u003Cbr>\u003Ctargetimage condition=\"end with\">calc.exe\u003C\u002Ftargetimage>\u003Cbr>\u003C\u002Fcreateremotethread>\u003Cbr>\u003C\u002Feventfiltering>\u003Cbr>\u003C\u002Fsysmon>\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Save as RecordCreateRemoteTh.xml\u003C\u002Fp>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>This configuration file monitors the calc.exe process and logs events when CreateRemoteThread is captured.\u003C\u002Fp>\u003Cp>Install configuration file:\u003C\u002Fp>\u003Cp>Sysmon.exe -c RecordCreateRemoteTh.xml\u003C\u002Fp>\u003Cp>As shown in the figure\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770015601947_3_63e48eef99.jpeg\">\u003C\u002Fp>\u003Cp>View configuration information\u003C\u002Fp>\u003Cp>Sysmon.exe -c\u003C\u002Fp>\u003Cp>As shown in the figure\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770015604336_4_7fc4ba53ab.jpeg\">\u003C\u002Fp>\u003Cp>Start calc.exe\u003C\u002Fp>\u003Cp>Execute CreateRemoteTh.exe, calc.exe is injected, a pop-up appears, as shown in the figure\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770015606575_5_92ce8a698c.jpeg\">\u003C\u002Fp>\u003Cp>The source code of CreateRemoteTh.exe can be referenced from:\u003C\u002Fp>\u003Cp>An open-source project\u003C\u002Fp>\u003Cp>Check the logs, Event ID 8 is found\u003C\u002Fp>\u003Cp>As shown below, CreateRemoteThread is detected\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770015608562_6_96f82fbf81.jpeg\">\u003C\u002Fp>\u003Cp>View Event ID 8 via PowerShell\u003C\u002Fp>\u003Cp>Get-WinEvent -FilterHashtable @{logname=\"Microsoft-Windows-Sysmon\u002FOperational\";ID=8}\u003C\u002Fp>\u003Cp>As shown below, retrieve log Event ID 8\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770015611351_7_4ddc2cdb69.jpeg\">\u003C\u002Fp>\u003Ch2>0x03 C++ Implementation of DLL Injection via APC\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>Using APC Injection:\u003C\u002Fp>\u003Cp>Code as follows:\u003C\u002Fp>\u003Cp>An open-source project\u003C\u002Fp>\u003Cp>For detailed explanation of the code, refer to:\u003C\u002Fp>\u003Cp>http:\u002F\u002Fblogs.microsoft.co.il\u002Fpavely\u002F2017\u002F03\u002F14\u002Finjecting-a-dll-without-a-remote-thread\u002F\u003C\u002Fp>\u003Cp>As shown, successfully injected into calc.exe\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770015613030_8_9fae922048.jpeg\">\u003C\u002Fp>\u003Cp>Using ProcessExplorer to view DLLs loaded by calc.exe, as shown below, testdll successfully injected\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770015614373_9_87933fc3c2.jpeg\">\u003C\u002Fp>\u003Cp>Checking logs, no Event ID 8 generated, successfully bypassed Sysmon monitoring of CreateRemoteThread\u003C\u002Fp>\u003Ch2>0x04 C# Implementation Code and Usage Shared by Casey Smith@subTee\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>Can be applied to exploitation using InstallUtil.exe and Msbuild.exe\u003C\u002Fp>\u003Cp>\u003Cstrong>InstallUtil.exe:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>https:\u002F\u002Fgist.github.com\u002FsubTee\u002F7bbd8e995ed8e8b1f8dab1dc926def8a\u003C\u002Fp>\u003Cp>\u003Cstrong>Msbuild.exe:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>https:\u002F\u002Fgist.github.com\u002FsubTee\u002Fcf3e1b06cf58fcc9e0255190d30c2d38\u003C\u002Fp>\u003Cp>No Event ID 8 was generated during the call\u003C\u002Fp>\u003Ch2>0x05 Summary\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>This article tests the monitoring capabilities of Sysmon and introduces how to achieve DLL injection via APC to bypass Sysmon's monitoring of CreateRemoteThread\u003C\u002Fp>\u003Cp>In specific environments, if manually shutting down the Sysmon service is not possible, utilizing APC can to some extent bypass Sysmon's monitoring of CreateRemoteThread\u003C\u002Fp>\u003Cp>\u003Cstrong>References:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>http:\u002F\u002Fsubt0x10.blogspot.com\u002F2017\u002F01\u002Fshellcode-injection-via-queueuserapc.html\u003C\u002Fp>\u003Cp>https:\u002F\u002Fwww.darkoperator.com\u002Fblog\u002F2014\u002F8\u002F8\u002Fsysinternals-sysmon\u003C\u002Fp>\u003Cp>http:\u002F\u002Fwww.freebuf.com\u002Fsectool\u002F122779.html\u003C\u002Fp>\u003Cp>http:\u002F\u002Fwww.cnblogs.com\u002FuAreKongqi\u002Fp\u002F6012353.html\u003C\u002Fp>\u003Cp>http:\u002F\u002Fblogs.microsoft.co.il\u002Fpavely\u002F2017\u002F03\u002F14\u002Finjecting-a-dll-without-a-remote-thread\u002F\u003C\u002Fp>\u003C\u002Fbody>\u003C\u002Fhtml>","text","ltr","\u003Chtml>\u003Chead>\u003C\u002Fhead>\u003Cbody>\u003Ch2>0x00 Preface\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>To perform remote injection into a specified process, the Windows API CreateRemoteThread is typically used to create a remote thread, thereby injecting a DLL or executing shellcode.\u003C\u002Fp>\u003Cp>Sysmon can be used to monitor and log system activities, including CreateRemoteThread operations.\u003C\u002Fp>\u003Cp>CreateRemoteThread is not the only injection method; can other injection techniques bypass Sysmon monitoring?\u003C\u002Fp>\u003Cp>Casey Smith @subTee provided the answer in his article:\u003C\u002Fp>\u003Cp>Shellcode Injection via QueueUserAPC - Hiding From Sysmon\u003C\u002Fp>\u003Cp>\u003Cstrong>The address is as follows:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>http:\u002F\u002Fsubt0x10.blogspot.com\u002F2017\u002F01\u002Fshellcode-injection-via-queueuserapc.html\u003C\u002Fp>\u003Ch2>0x01 Introduction\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>This article will cover the following topics:\u003C\u002Fp>\u003Cul>\u003Cli>Sysmon configuration testing to monitor CreateRemoteThread operations\u003C\u002Fli>\u003Cli>C++ implementation of DLL injection via APC\u003C\u002Fli>\u003Cli>Bypassing Sysmon Testing\u003C\u002Fli>\u003Cli>C# implementation code and usage shared by Casey Smith@subTee\u003C\u002Fli>\u003C\u002Ful>\u003Ch3>Sysmon:\u003C\u002Fh3>\u003Cp>Can be used to monitor and record system activities, logging to Windows event logs, including the following events:\u003C\u002Fp>\u003Cul>\u003Cli>Event ID 1: Process creation\u003C\u002Fli>\u003Cli>Event ID 2: A process changed a file creation time\u003C\u002Fli>\u003Cli>Event ID 3: Network connection\u003C\u002Fli>\u003Cli>Event ID 4: Sysmon service state changed\u003C\u002Fli>\u003Cli>Event ID 5: Process terminated\u003C\u002Fli>\u003Cli>Event ID 6: Driver loaded\u003C\u002Fli>\u003Cli>Event ID 7: Image loaded\u003C\u002Fli>\u003Cli>Event ID 8: CreateRemoteThread\u003C\u002Fli>\u003Cli>Event ID 9: RawAccessRead\u003C\u002Fli>\u003Cli>Event ID 10: ProcessAccess\u003C\u002Fli>\u003Cli>Event ID 11: FileCreate\u003C\u002Fli>\u003Cli>Event ID 12: RegistryEvent (Object create and delete)\u003C\u002Fli>\u003Cli>Event ID 13: RegistryEvent (Value Set)\u003C\u002Fli>\u003Cli>Event ID 14: RegistryEvent (Key and Value Rename)\u003C\u002Fli>\u003Cli>Event ID 15: FileCreateStreamHash\u003C\u002Fli>\u003Cli>Event ID 255: Error\u003C\u002Fli>\u003C\u002Ful>\u003Cp>For details, see https:\u002F\u002Ftechnet.microsoft.com\u002Fen-us\u002Fsysinternals\u002Fsysmon\u003C\u002Fp>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>CreateRemoteThread is Event ID 8\u003C\u002Fp>\u003Ch3>DLL injection\u003C\u002Fh3>\u003Cp>Common methods:\u003C\u002Fp>\u003Cul>\u003Cli>Create a new thread\u003C\u002Fli>\u003Cli>Set thread context, modify registers\u003C\u002Fli>\u003Cli>Insert into APC queue\u003C\u002Fli>\u003Cli>Modify registry\u003C\u002Fli>\u003Cli>Hook window messages\u003C\u002Fli>\u003Cli>Remote Manual Implementation of LoadLibrary\u003C\u002Fli>\u003C\u002Ful>\u003Cp>Cited from http:\u002F\u002Fwww.cnblogs.com\u002FuAreKongqi\u002Fp\u002F6012353.html\u003C\u002Fp>\u003Ch3>Shellcode Injection via QueueUserAPC - Hiding From Sysmon:\u003C\u002Fh3>\u003Cp>C# implementation, executing shellcode by calling QueueUserAPC, applicable to InstallUtil.exe and Msbuild.exe, capable of bypassing Sysmon's monitoring of Event ID 8: CreateRemoteThread\u003C\u002Fp>\u003Cp>\u003Cstrong>Article URL:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>http:\u002F\u002Fsubt0x10.blogspot.com\u002F2017\u002F01\u002Fshellcode-injection-via-queueuserapc.html\u003C\u002Fp>\u003Ch2>0x02 Introduction to Sysmon\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>\u003Cstrong>Download URL:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>https:\u002F\u002Ftechnet.microsoft.com\u002Fen-us\u002Fsysinternals\u002Fsysmon\u003C\u002Fp>\u003Cp>Installed on the system as a system service and driver\u003C\u002Fp>\u003Cp>Used to monitor and log system activities, recording them into Windows event logs\u003C\u002Fp>\u003Cp>Provides detailed information on operations such as process creation, network connections, and file creation time changes\u003C\u002Fp>\u003Cp>Through event logs, abnormal activities can be identified to understand attackers' operations on the network\u003C\u002Fp>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>After installing Sysmon on the system, a new service named Sysmon is added\u003C\u002Fp>\u003Cp>As shown in the figure\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770015591191_0_310355993a-1.jpeg\">\u003C\u002Fp>\u003Cp>That is to say, if an attacker gains host privileges, they can see the installation of Sysmon by viewing the installed services\u003C\u002Fp>\u003Ch3>Installation\u003C\u002Fh3>\u003Cp>Install with default configuration:\u003C\u002Fp>\u003Cp>sysmon -accepteula –i -n\u003C\u002Fp>\u003Cp>Install with configuration file:\u003C\u002Fp>\u003Cp>sysmon -c config.xml\u003C\u002Fp>\u003Cp>Example format of the configuration file config.xml is as follows:\u003C\u002Fp>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>XML is case-sensitive\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>\u003Csysmon schemaversion=\"3.20\">      \u003Cbr>\u003C!-- Capture all hashes -->      \u003Cbr>\u003Chashalgorithms>*\u003C\u002Fhashalgorithms>      \u003Cbr>\u003Ceventfiltering>        \u003Cbr>\u003C!-- Log all drivers except if the signature -->       \u003Cbr> \u003C!-- contains Microsoft or Windows -->       \u003Cbr> \u003Cdriverload onmatch=\"exclude\">          \u003Cbr>\u003Csignature condition=\"contains\">microsoft\u003C\u002Fsignature>         \u003Cbr> \u003Csignature condition=\"contains\">windows\u003C\u002Fsignature>        \u003Cbr>\u003C\u002Fdriverload>       \u003Cbr> \u003C!-- Do not log process termination -->        \u003Cbr>\u003Cprocessterminate onmatch=\"include\">       \u003Cbr> \u003C!-- Log network connection if the destination port equal 443 -->        \u003Cbr>\u003C!-- or 80, and process isn't InternetExplorer -->        \u003Cbr>\u003Cnetworkconnect onmatch=\"include\">          \u003Cbr>\u003Cdestinationport>443\u003C\u002Fdestinationport>          \u003Cbr>\u003Cdestinationport>80\u003C\u002Fdestinationport>        \u003Cbr>\u003C\u002Fnetworkconnect>        \u003Cbr>\u003Cnetworkconnect onmatch=\"exclude\">          \u003Cbr>\u003Cimg condition=\"end with\">iexplore.exe       \u003Cbr> \u003C\u002Fnetworkconnect>     \u003Cbr> \u003C\u002Fprocessterminate>\u003C\u002Feventfiltering>    \u003Cbr>\u003C\u002Fsysmon>\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>This example is referenced from http:\u002F\u002Fwww.freebuf.com\u002Fsectool\u002F122779.html\u003C\u002Fp>\u003Ch3>View Configuration\u003C\u002Fh3>\u003Cp>sysmon -c\u003C\u002Fp>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Configuration properties are saved in the registry at the following location:\u003C\u002Fp>\u003Cp>HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\SysmonDrv\\Parameters\u003C\u002Fp>\u003Cp>As shown in the figure\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770015595997_1_da568a1d78-1.jpeg\">\u003C\u002Fp>\u003Ch3>View Log Records\u003C\u002Fh3>\u003Cp>1. Via the panel\u003C\u002Fp>\u003Cp>Location as follows:\u003C\u002Fp>\u003Cp>Control Panel\\System and Security-View event logs\u003C\u002Fp>\u003Cp>Applications and Services Logs-Microsoft-Windows-Sysmon-Operational\u003C\u002Fp>\u003Cp>As shown in the figure\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770015599288_2_fa2d80eb55-1.jpeg\">\u003C\u002Fp>\u003Cp>2. View via PowerShell, command as follows:\u003C\u002Fp>\u003Cp>(Administrator privileges)\u003C\u002Fp>\u003Cp>Get-WinEvent -FilterHashtable @{logname=\"Microsoft-Windows-Sysmon\u002FOperational\";}\u003C\u002Fp>\u003Ch3>Monitor and log CreateRemoteThread\u003C\u002Fh3>\u003Cp>Configuration file as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>\u003Csysmon schemaversion=\"3.20\">      \u003Cbr>\u003C!-- Capture all hashes -->      \u003Cbr>\u003Chashalgorithms>*\u003C\u002Fhashalgorithms>      \u003Cbr> \u003Ceventfiltering>        \u003Cbr>\u003C!-- Log all drivers except if the signature -->\u003Cbr> \u003C!-- contains Microsoft or Windows -->\u003Cbr>\u003Ccreateremotethread onmatch=\"include\">\u003Cbr>\u003Ctargetimage condition=\"end with\">calc.exe\u003C\u002Ftargetimage>\u003Cbr>\u003C\u002Fcreateremotethread>\u003Cbr>\u003C\u002Feventfiltering>\u003Cbr>\u003C\u002Fsysmon>\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Save as RecordCreateRemoteTh.xml\u003C\u002Fp>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>This configuration file monitors the calc.exe process and logs events when CreateRemoteThread is captured.\u003C\u002Fp>\u003Cp>Install configuration file:\u003C\u002Fp>\u003Cp>Sysmon.exe -c RecordCreateRemoteTh.xml\u003C\u002Fp>\u003Cp>As shown in the figure\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770015601947_3_63e48eef99-1.jpeg\">\u003C\u002Fp>\u003Cp>View configuration information\u003C\u002Fp>\u003Cp>Sysmon.exe -c\u003C\u002Fp>\u003Cp>As shown in the figure\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770015604336_4_7fc4ba53ab-1.jpeg\">\u003C\u002Fp>\u003Cp>Start calc.exe\u003C\u002Fp>\u003Cp>Execute CreateRemoteTh.exe, calc.exe is injected, a pop-up appears, as shown in the figure\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770015606575_5_92ce8a698c-1.jpeg\">\u003C\u002Fp>\u003Cp>The source code of CreateRemoteTh.exe can be referenced from:\u003C\u002Fp>\u003Cp>An open-source project\u003C\u002Fp>\u003Cp>Check the logs, Event ID 8 is found\u003C\u002Fp>\u003Cp>As shown below, CreateRemoteThread is detected\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770015608562_6_96f82fbf81-1.jpeg\">\u003C\u002Fp>\u003Cp>View Event ID 8 via PowerShell\u003C\u002Fp>\u003Cp>Get-WinEvent -FilterHashtable @{logname=\"Microsoft-Windows-Sysmon\u002FOperational\";ID=8}\u003C\u002Fp>\u003Cp>As shown below, retrieve log Event ID 8\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770015611351_7_4ddc2cdb69-1.jpeg\">\u003C\u002Fp>\u003Ch2>0x03 C++ Implementation of DLL Injection via APC\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>Using APC Injection:\u003C\u002Fp>\u003Cp>Code as follows:\u003C\u002Fp>\u003Cp>An open-source project\u003C\u002Fp>\u003Cp>For detailed explanation of the code, refer to:\u003C\u002Fp>\u003Cp>http:\u002F\u002Fblogs.microsoft.co.il\u002Fpavely\u002F2017\u002F03\u002F14\u002Finjecting-a-dll-without-a-remote-thread\u002F\u003C\u002Fp>\u003Cp>As shown, successfully injected into calc.exe\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770015613030_8_9fae922048-1.jpeg\">\u003C\u002Fp>\u003Cp>Using ProcessExplorer to view DLLs loaded by calc.exe, as shown below, testdll successfully injected\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770015614373_9_87933fc3c2-1.jpeg\">\u003C\u002Fp>\u003Cp>Checking logs, no Event ID 8 generated, successfully bypassed Sysmon monitoring of CreateRemoteThread\u003C\u002Fp>\u003Ch2>0x04 C# Implementation Code and Usage Shared by Casey Smith@subTee\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>Can be applied to exploitation using InstallUtil.exe and Msbuild.exe\u003C\u002Fp>\u003Cp>\u003Cstrong>InstallUtil.exe:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>https:\u002F\u002Fgist.github.com\u002FsubTee\u002F7bbd8e995ed8e8b1f8dab1dc926def8a\u003C\u002Fp>\u003Cp>\u003Cstrong>Msbuild.exe:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>https:\u002F\u002Fgist.github.com\u002FsubTee\u002Fcf3e1b06cf58fcc9e0255190d30c2d38\u003C\u002Fp>\u003Cp>No Event ID 8 was generated during the call\u003C\u002Fp>\u003Ch2>0x05 Summary\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>This article tests the monitoring capabilities of Sysmon and introduces how to achieve DLL injection via APC to bypass Sysmon's monitoring of CreateRemoteThread\u003C\u002Fp>\u003Cp>In specific environments, if manually shutting down the Sysmon service is not possible, utilizing APC can to some extent bypass Sysmon's monitoring of CreateRemoteThread\u003C\u002Fp>\u003Cp>\u003Cstrong>References:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>http:\u002F\u002Fsubt0x10.blogspot.com\u002F2017\u002F01\u002Fshellcode-injection-via-queueuserapc.html\u003C\u002Fp>\u003Cp>https:\u002F\u002Fwww.darkoperator.com\u002Fblog\u002F2014\u002F8\u002F8\u002Fsysinternals-sysmon\u003C\u002Fp>\u003Cp>http:\u002F\u002Fwww.freebuf.com\u002Fsectool\u002F122779.html\u003C\u002Fp>\u003Cp>http:\u002F\u002Fwww.cnblogs.com\u002FuAreKongqi\u002Fp\u002F6012353.html\u003C\u002Fp>\u003Cp>http:\u002F\u002Fblogs.microsoft.co.il\u002Fpavely\u002F2017\u002F03\u002F14\u002Finjecting-a-dll-without-a-remote-thread\u002F\u003C\u002Fp>\u003C\u002Fbody>\u003C\u002Fhtml>",314,"Onedaysec",4,"published","2026-02-02T07:25:19.985Z",{"title":37,"description":14,"keywords":38,"ogImage":39,"canonicalUrl":39,"noIndex":40},"DLL Injection via APC: Bypass Sysmon Monitoring Guide","DLL injection, APC, Sysmon bypass, QueueUserAPC, CreateRemoteThread, shellcode injection, Windows security, C++ injection, C# code, process injection, evasion techniques",null,false,[],{"docs":43,"hasNextPage":40},[44,4,45,46],1064,1062,1061,{"title":39,"description":39,"image":39},"2026-07-24T15:37:09.914Z","2026-07-23T16:02:29.171Z","draft","2026-07-23T16:16:25.295Z"]