Waiting Thread Hijacking (WTH) is a novel process injection technique designed to avoid triggering common Endpoint Detection & Response (EDR) system alerts. By hijacking the flow of dormant waiting threads, rather than creating new threads or overtly suspending/resuming existing ones, WTH offers a stealthier method of executing
Table of contents
Key PointsIntroductionExecuting Remote CodeWhat Problems Waiting Thread Hijacking Solves?ImplementationDemoExecution flow obfuscationConclusionReferencesSort: