Exploit.ProcessHollowing is Malwarebytes' detection name for attempts to replace a legitimate process' memory with malicious code


Exploit.ProcessHollowing monitors, detects, and blocks attempts to replace a legitimate process' memory with malicious code. Attackers use process hollowing to remove code in an executable file and replaces it with malicious code. The process hollowing attack is used to avoid detection by running as a legitimate process.


Malwarebytes protects your system(s) by detecting attempts at process hollowing and displays this warning: Process Hollowing Protection

