{"id":"T1055.003","name":"Thread Execution Hijacking","url":"https://attack.mitre.org/techniques/T1055/003","tactics":["stealth","privilege-escalation"],"platforms":["Windows"],"live":true,"revoked":false,"deprecated":false,"revoked_by":null,"detection_strategies":[{"id":"DET0295","stix_id":"x-mitre-detection-strategy--47dd679b-1bd4-4bb7-a946-5d77fd49a939","name":"Behavioral Detection of Thread Execution Hijacking via Thread Suspension and Context Switching","url":"https://attack.mitre.org/detectionstrategies/DET0295","analytics":[{"id":"AN0822","stix_id":"x-mitre-analytic--26ef9aef-33eb-4df2-ba82-6ace95173c80","name":"Analytic 0822","description":"Detects hijacking of an existing thread (OpenThread) through a behavioral chain involving thread suspension (SuspendThread), memory modification (VirtualAllocEx + WriteProcessMemory), context manipulation (SetThreadContext), and thread resumption—all within another live process's address space (ResumeThread).","url":"https://attack.mitre.org/detectionstrategies/DET0295#AN0822","platforms":["Windows"],"log_source_references":[{"name":"WinEventLog:Sysmon","channel":"EventCode=10","data_component":"DC0035","data_component_name":"Process Access","log_source_slug":"wineventlog-sysmon"},{"name":"WinEventLog:Sysmon","channel":"EventCode=8","data_component":"DC0020","data_component_name":"Process Modification","log_source_slug":"wineventlog-sysmon"},{"name":"etw:Microsoft-Windows-Kernel-Process","channel":"API Calls","data_component":"DC0021","data_component_name":"OS API Execution","log_source_slug":"etw-microsoft-windows-kernel-process"},{"name":"WinEventLog:Sysmon","channel":"EventCode=1","data_component":"DC0032","data_component_name":"Process Creation","log_source_slug":"wineventlog-sysmon"}],"mutable_elements":[{"field":"TargetProcessList","description":"Sensitive processes that should never be targeted for thread hijack attempts"},{"field":"TimeWindow","description":"Expected delay between SuspendThread and ResumeThread events; tight thresholds reduce evasion"},{"field":"SuspiciousThreadContextRegions","description":"Memory regions or offsets that should not be targeted for SetThreadContext"},{"field":"ParentProcessAnomalyThreshold","description":"Score deviation of the parent/child relationship in a thread injection chain"}],"live":true,"detection_strategies":["DET0295"],"techniques":["T1055.003"]}],"live":true,"version":"1.0","techniques":["T1055.003"]}],"sigma_rules":[{"id":"7bdde3bf-2a42-4c39-aa31-a92b3e17afac","title":"HackTool - LittleCorporal Generated Maldoc Injection","author":"Christian Burkard (Nextron Systems)","status":"test","level":"high","date":"2021-08-09","modified":"2023-11-28","description":"Detects the process injection of a LittleCorporal generated Maldoc.","references":["https://github.com/connormcgarr/LittleCorporal"],"logsource":{"product":"windows","category":"process_access"},"tags":["attack.execution","attack.privilege-escalation","attack.stealth","attack.t1204.002","attack.t1055.003"],"path":"rules/windows/process_access/proc_access_win_hktl_littlecorporal_generated_maldoc.yml","techniques":["T1204.002","T1055.003"],"cves":[]},{"id":"a1a144b7-5c9b-4853-a559-2172be8d4a03","title":"Remote Thread Creation In Uncommon Target Image","author":"Florian Roth (Nextron Systems)","status":"test","level":"medium","date":"2022-03-16","modified":"2025-07-04","description":"Detects uncommon target processes for remote thread creation","references":["https://web.archive.org/web/20220319032520/https://blog.redbluepurple.io/offensive-research/bypassing-injection-detection"],"logsource":{"product":"windows","category":"create_remote_thread"},"tags":["attack.privilege-escalation","attack.stealth","attack.t1055.003"],"path":"rules/windows/create_remote_thread/create_remote_thread_win_susp_uncommon_target_image.yml","techniques":["T1055.003"],"cves":[]}],"kev_cves":[],"_built":"2026-08-24 19:45 UTC","_attack_version":"19.2","_sigma_commit":"da9bb07d642a2826e89702445d32c795209ec108"}