{"id":"T1055.013","name":"Process Doppelgänging","url":"https://attack.mitre.org/techniques/T1055/013","tactics":["stealth","privilege-escalation"],"platforms":["Windows"],"live":true,"revoked":false,"deprecated":false,"revoked_by":null,"detection_strategies":[{"id":"DET0544","stix_id":"x-mitre-detection-strategy--8373cca7-feb8-44e4-94d0-fc39ea3586d7","name":"Detection Strategy for Process Doppelgänging on Windows","url":"https://attack.mitre.org/detectionstrategies/DET0544","analytics":[{"id":"AN1501","stix_id":"x-mitre-analytic--37d6450b-6c90-48dd-b69d-161099913851","name":"Analytic 1501","description":"Detects adversary abuse of Transactional NTFS (TxF) and undocumented process loading mechanisms (e.g., NtCreateProcessEx) to create a hollowed process from an uncommitted, maliciously tainted file image in memory, later executed via NtCreateThreadEx.","url":"https://attack.mitre.org/detectionstrategies/DET0544#AN1501","platforms":["Windows"],"log_source_references":[{"name":"WinEventLog:Sysmon","channel":"EventCode=1","data_component":"DC0032","data_component_name":"Process Creation","log_source_slug":"wineventlog-sysmon"},{"name":"WinEventLog:Sysmon","channel":"EventCode=10","data_component":"DC0035","data_component_name":"Process Access","log_source_slug":"wineventlog-sysmon"},{"name":"WinEventLog:Sysmon","channel":"EventCode=11","data_component":"DC0039","data_component_name":"File Creation","log_source_slug":"wineventlog-sysmon"},{"name":"etw:Microsoft-Windows-Kernel-Process","channel":"CreateTransaction, CreateFileTransacted, RollbackTransaction, NtCreateProcessEx, NtCreateThreadEx","data_component":"DC0021","data_component_name":"OS API Execution","log_source_slug":"etw-microsoft-windows-kernel-process"}],"mutable_elements":[{"field":"TransactionExecutableNamePattern","description":"Pattern of legitimate executables often used as doppelgänging targets (e.g., svchost.exe, calc.exe)"},{"field":"TimeWindow_TransactionToExecution","description":"Time delta between TxF rollback and thread creation in hollowed process"},{"field":"ThreadStartEntropyThreshold","description":"Entropy level of thread start address in memory used to detect obfuscated shellcode"},{"field":"TxF API Call Frequency Threshold","description":"Limit on CreateTransaction + RollbackTransaction sequences per process"}],"live":true,"detection_strategies":["DET0544"],"techniques":["T1055.013"]}],"live":true,"version":"1.0","techniques":["T1055.013"]}],"sigma_rules":[],"kev_cves":[],"_built":"2026-08-24 19:45 UTC","_attack_version":"19.2","_sigma_commit":"da9bb07d642a2826e89702445d32c795209ec108"}