Early Cascade Injection: From Windows process creation to stealthy injection
outflank.nl
outflank.nl
Business-wise our work on this went down once Microsoft Detours was made FOSS even when our products has other capabilities. A good old thread is here [4].
[1] https://github.com/nektra/Deviare2
[2] https://github.com/nektra/Deviare-InProc
[3] https://github.com/nektra/RemoteBridge
[4] https://www.reddit.com/r/programming/comments/22crn0/gpl_alt...
It works to this day, despite looking exactly like what malware would do. My tool is nothing in the grand scheme, but I suspect I'm not the only one doing these sort of shenanigans, and no doubt some big important app is doing it and can't be bothered to fix itself, so MS is stuck supporting it.
Typically but not always, the process with address space that is being
written to is being debugged.
I don't really see why you'd need admin rights to do so. As far as the process being injected belongs to the same user and is not a protected process (DRM), OpenProcess will happily return a handle with PROCESS_VM_WRITE and PROCESS_VM_OPERATION rights as required by WriteProcessMemory.On the other hand, if you want to inject a system process, you definitely need admin rights.
Only if the process calling it has SE_DEBUG_NAME privileges, which you must set by opening your own process and then calling AdjustTokenPrivileges. But that will fail unless you have the "Debug Programs" right enabled in the security policy.
It’s not complicated, if you want to buy secure software, don’t use Windows.
In a previous life where I had to find a way to stealthily inject Chrome (in the presence of good anti-viruses), the solution was to find an obscure type of Windows shell extension which if registered would automatically be loaded by Windows into Chrome without triggering an alert.