Process Ghosting
Marking a payload file delete-pending before mapping it into a section and creating a process, so the executable is gone from disk by the time the process runs — leaving no scannable image file.
Process Ghosting is a close cousin of Doppelgänging that avoids TxF entirely. The attacker creates a file, immediately puts it into a delete-pending state, writes the malicious payload, maps an image section from the still-open handle, and then closes the handle — which finalizes the deletion. A process is then created from the section, so it executes from an image whose backing file no longer exists, defeating image-on-disk scanning and many EDR file callbacks.
How it works
Setting FileDispositionInformation with DeleteFile = TRUE schedules the file
for deletion when the last handle closes, but the file remains writable and
mappable until then. The image section is created while the handle is still open,
so the loader reads the payload; closing the handle deletes the file but leaves
the section object valid for NtCreateProcessEx.
hFile = CreateFileW(path, ..., DELETE | GENERIC_WRITE/READ, ...)
NtSetInformationFile(hFile, FileDispositionInformation, {DeleteFile=TRUE})
WriteFile(hFile, maliciousPayload, len)
NtCreateSection(&hSection, ..., SEC_IMAGE, hFile) // section from delete-pending file
CloseHandle(hFile) // file is now deleted from disk
NtCreateProcessEx(&hProc, ..., hSection, ...) // process from the section
NtCreateThreadEx(&hThread, ..., hProc, entryPoint, ...)Detection & bypass
- Static — The loader imports
NtSetInformationFile(used withFileDispositionInformation/FileDispositionInformationEx) together withNtCreateSection(SEC_IMAGE),NtCreateProcessEx, andNtCreateThreadEx. TheDELETEaccess flag onCreateFilefollowed by section creation on the same handle is a distinctive code pattern rarely seen in benign loaders. - Dynamic — Watch for a
CreateFileopened withDELETEaccess, aSetInformationFiledelete-disposition call, payload write, image-section creation, and aCloseHandlethat deletes the file before the new process is fully constructed. A minifilter / file-system callback observing a section mapped from a file that is then immediately deleted is the canonical trigger. - Memory forensics — The running process's main image file is deleted or inaccessible: querying the image path yields a path that no longer exists on disk, or the section has no valid backing file. Moneta and pe-sieve flag the main module as unbacked / disk-mismatch; Volatility shows a VAD image whose file object points at a vanished or delete-pending file.
- Tools — Minifilter / EDR file callbacks, Sysmon/ETW (file + process
events), Process Hacker, Moneta, pe-sieve, and Volatility (image-path vs. disk,
vadinfo,filescan). Elastic and several EDRs ship dedicated ghosting rules keyed on the delete-pending-then-execute sequence.