Exploit.ProcessHollowing

detection icon

Short bio

Exploit.ProcessHollowing is Malwarebytes’ detection name for attempts to replace a legitimate process’ memory with malicious code

Technique

Exploit.ProcessHollowing monitors, detects, and blocks attempts to replace a legitimate process’ memory with malicious code. Attackers use process hollowing to remove code in an executable file and replaces it with malicious code. The process hollowing attack is used to avoid detection by running as a legitimate process.

Protection

Malwarebytes protects your system(s) by detecting attempts at process hollowing and displays this warning: Process Hollowing Protection

list of Exploit detections in Nebula