📣 Send us your press release
Site updates every 15 minutes
Technology

Picus Security Analyzes MITRE ATT&CK Process Injection Technique

Picus Security has published an analysis of the Portable Executable (PE) Injection technique (MITRE ATT&CK T1055.002), detailing how adversaries use it to execute malicious code stealthily.

9 October 2026

Cybersecurity firm Picus Security has released a detailed analysis of the Portable Executable (PE) Injection technique, identified as T1055.002 within the MITRE ATT&CK framework. This method allows adversaries to execute malicious code by injecting an entire Portable Executable file directly into the memory of a legitimate process.

The technique is prevalent in modern cyberattacks as it facilitates stealthy execution. Unlike traditional methods that write executable files to disk, PE injection enables attackers to run malicious code without leaving traces on the file system, making detection by antivirus and endpoint detection and response (EDR) solutions more challenging.

Picus Security's blog post explains how attackers employ PE injection, providing real-world attack examples. The process typically involves using the Windows API function WriteProcessMemory to write malicious code into the target process's memory, rather than injecting a DLL path.

A key challenge for attackers is that the injected code acquires an unpredictable base address in the target process's memory. Adversaries often overcome this by designing their malware to locate the host process's relocation table and resolve absolute addresses within the injected code.

Picus Security focuses on providing services for testing and simulating cyber threats, aiming to help organizations understand and improve their defenses against known attack methodologies.

Original source: picussecurity.com