Skip to content

Process Ghosting

Marking a payload file delete-pending before mapping it into a section and creating a process, so the executable is gone from disk by the time the process runs — leaving no scannable image file.

Process Ghosting is a close cousin of Doppelgänging that avoids TxF entirely. The attacker creates a file, immediately puts it into a delete-pending state, writes the malicious payload, maps an image section from the still-open handle, and then closes the handle — which finalizes the deletion. A process is then created from the section, so it executes from an image whose backing file no longer exists, defeating image-on-disk scanning and many EDR file callbacks.

How it works

Setting FileDispositionInformation with DeleteFile = TRUE schedules the file for deletion when the last handle closes, but the file remains writable and mappable until then. The image section is created while the handle is still open, so the loader reads the payload; closing the handle deletes the file but leaves the section object valid for NtCreateProcessEx.

text
hFile = CreateFileW(path, ..., DELETE | GENERIC_WRITE/READ, ...)
NtSetInformationFile(hFile, FileDispositionInformation, {DeleteFile=TRUE})
WriteFile(hFile, maliciousPayload, len)
NtCreateSection(&hSection, ..., SEC_IMAGE, hFile)    // section from delete-pending file
CloseHandle(hFile)                                   // file is now deleted from disk
NtCreateProcessEx(&hProc, ..., hSection, ...)         // process from the section
NtCreateThreadEx(&hThread, ..., hProc, entryPoint, ...)

Detection & bypass

  • Static — The loader imports NtSetInformationFile (used with FileDispositionInformation/FileDispositionInformationEx) together with NtCreateSection(SEC_IMAGE), NtCreateProcessEx, and NtCreateThreadEx. The DELETE access flag on CreateFile followed by section creation on the same handle is a distinctive code pattern rarely seen in benign loaders.
  • Dynamic — Watch for a CreateFile opened with DELETE access, a SetInformationFile delete-disposition call, payload write, image-section creation, and a CloseHandle that deletes the file before the new process is fully constructed. A minifilter / file-system callback observing a section mapped from a file that is then immediately deleted is the canonical trigger.
  • Memory forensics — The running process's main image file is deleted or inaccessible: querying the image path yields a path that no longer exists on disk, or the section has no valid backing file. Moneta and pe-sieve flag the main module as unbacked / disk-mismatch; Volatility shows a VAD image whose file object points at a vanished or delete-pending file.
  • Tools — Minifilter / EDR file callbacks, Sysmon/ETW (file + process events), Process Hacker, Moneta, pe-sieve, and Volatility (image-path vs. disk, vadinfo, filescan). Elastic and several EDRs ship dedicated ghosting rules keyed on the delete-pending-then-execute sequence.
Votes

Comments(0)