Bypassing Network Activity Monitors using Process Hollowing

Jean Rosemond Dora, Ladislav Hluchý · 2025

Monitoring network activities is a crucial approach when dealing with defensive cybersecurity. It can help find traffic anomalies and block unusual activities when applied in an environment. Statistics show that Microsoft Windows dominates the global desktop operating systems (OS) by 72%. We therefore centralized this research on Windows OS. When attackers get into a system from an external attack, they may use the process injection and migration to inject their code into a process that typically starts when the OS boots to obtain and maintain stability. These techniques will allow them to perform post-exploitations smoothly. However, attackers may still not have enough access rights to execute further attacks since network monitoring software can flag their activities and terminate the process that generates them. We will address this brilliant technique known as "Process Hollowing" to overcome this challenge. We will succinctly explain the migration process and the importance of the hollowing process. We will deepen our analysis to bypass network security and a synopsis of the mitigation techniques that can help security researchers, penetration testers, and red teaming in future engagements.

Read the paper · More papers on PaperTik