WCU / Cybersecurity
~/CSC 471/Class 06
CSC 471 · Class 06

DLL Injection

21 knowledge points. Work through them in order, or jump to any topic.

//

Knowledge Points

01What Is DLL Injection? 02Why Attackers (and Defenders) Use It 03Process Address Space and Modules 04The Two Functions at the Heart of It 05The Classic Technique: Overview 06Sequence Diagram 07Condensed C Sketch 08What DllMain Sees 09SetWindowsHookEx 10AppInit_DLLs (Legacy) 11Reflective DLL Injection 12APC Injection (QueueUserAPC) 13Process Hollowing (RunPE) 14Thread Execution Hijacking 15Modern Twists: Early Bird and Module Stomping 16Technique Cheat Sheet 17Detecting Injection: The API Trail 18Detecting Injection: Modules, Hooks, ETW 19Lab 3: Inject Into Notepad 20Lab 3: Deliverables and Tips 21Summary