Course Overview

Modern attackers increasingly rely on stealthy and sophisticated techniques to gain persistence, escalate privileges, and evade defenses. Process Injection stands at the forefront of these tactics, allowing malicious code to run under the guise of legitimate processes. This course provides a comprehensive exploration of process injection across Windows and Linux, detailing methods such as DLL Injection, Process Hollowing, Doppelgänging, APC Injection, Thread Local Storage, and more. 

You will learn how these methods work at a technical level, from how attackers allocate and write into memory to how they bypass user-mode hooks and hide malicious actions. You will also discover detection best practices using Sysmon, Process Monitor, Process Explorer, Sigma, and YARA, and prevention strategies, such as leveraging firewalls, whitelisting, EDR policies, and SIEM integration. Finally, you will delve into Mockingjay, a newly discovered injection method, to stay ahead of emerging threats and build a robust, layered security posture. 

By the end of this course, you will possess the knowledge and skills to identify, analyze, and defend against a wide variety of process injection attacks, enabling you to confidently protect your organization’s digital infrastructure against evolving adversarial tactics. 

What You Will Learn

  • The fundamentals of process injection and its role in modern threat landscapes.
  • The sub-techniques of process injection (DLL Injection, PE Injection, APC, Process Hollowing, etc.) across Windows and Linux.
  • Lab-based detection methods, leveraging Sysmon, Process Monitor, Process Explorer, Sigma, and YARA to identify malicious injections.
  • Prevention and remediation strategies, including firewalls, whitelisting, EDR solutions, and SIEM integrations to block or mitigate injection attacks.
  • Emerging injection methods, such as Mockingjay, and how to proactively adapt your defenses against newly discovered threats.

Program Curriculum

  • High-level Overview of Course
  • The Significance of Process Injection in Modern Threats
  • Common Evasion Techniques & Process Injection’s Role
  • Chapter 1 Quiz

  • Installing VirtualBox and Creating a Windows 10 VM
  • Linux VM Setup for ptrace & VDSO Testing
  • Installing Sysmon, Sysinternals & Microsoft Defender for Endpoint (ATP)
  • Additional Tools
  • Chapter 2 Quiz

  • Dynamic-Link Library (DLL) Injection
  • Portable Executable (PE) Injection
  • Thread Execution Hijacking
  • Asynchronous Procedure Call (APC)
  • Chapter 3 Quiz

  • Thread Local Storage
  • ptrace System Calls
  • Extra Window Memory Injection
  • Process Hollowing
  • Process Doppelgänging
  • VDSO Hijacking
  • ListPlanting
  • Chapter 4 Quiz

  • Process Injection IoCs & Sysmon Event Correlation
  • Malicious PowerShell & Script Block Logging
  • Threat Detection with Sigma
  • YARA for Injection Detection
  • Chapter 5 Quiz

  • Understanding the Mockingjay Process Injection
  • Security Implications & Evasion Tactics
  • Complete Execution Flow of Mockingjay
  • Detection & Remediation Measures
  • Chapter 6 Quiz

  • Blacklisting & Whitelisting (AppLocker, WDAC)
  • Configuring SIEM Tools to Monitor Suspicious Events
  • Microsoft Defender for Endpoint
  • Comprehensive Checklist for Monitoring, Detection & Defense
  • Chapter 7 Quiz

  • Summary of Key Takeaways
  • EC-Council’s C,TIA & Next Steps
Load more modules

Instructor

Seif Eddine

Ing.Seif (Seif Eddine) is an engineer specializing in Big Data and Cybersecurity, grounded in early immersion in ethical hacking. He provides security consulting, bug hunting, and advanced threat analysis to organizations worldwide. Over the years, he discovered a passion for teaching and has since developed multiple courses that merge robust technical depth with practical cybersecurity applications. Leveraging his extensive expertise in automation, threat detection, and digital forensics, Seif empowers clients and students alike to safeguard critical digital assets in an increasingly complex threat landscape.

Join over 1 Million professionals from the most renowned Companies in the world!

certificate

Choose the Pro Plan That Fits Your Learning Journey

Invest in your future with flexible Pro subscription plans. Whether you're starting your cybersecurity journey or expanding your expertise, choose the membership duration that works for you and gain access to our complete learning platform.

Monthly Plans
Annual Plans
Save 20% with our annual plans!

Pro

Ideal for continuous learning, offering extensive resources with 900+ courses and diverse Learning Paths to enhance your skills.

$ 599.00
Billed annually or $69.00 billed monthly

What is included

  • Access to 900+ Premium Short Courses
  • 70+ Structured Learning Paths
  • Validation of Completion with All Courses and Learning Paths
  • New Courses Added Every Month
Early Access Offer

Pro +

Experience immersive learning with Practice Labs and CTF Challenges for comprehensive skill-building.

$ 699.00
Billed annually or $79.00 billed monthly

Everything in Pro and

  • 500+ Practice Labs with Guided Instructions
  • 400+ CTF Challenges with Detailed Walkthroughs
  • New Practice Labs and Challenges Added Every Month

Related Courses

1 of 50