Section Mapping Injection
Injecting code without WriteProcessMemory by mapping a shared section into both the local and remote process, writing shellcode through the local view, then executing it from the remote view.
Section mapping injection delivers a payload into a remote process without ever
calling WriteProcessMemory, defeating the most heavily monitored injection API.
The attacker creates a memory-backed section object and maps two views of it: a
read/write view in the local process and a read/execute view in the
remote process. Shellcode written through the local view is immediately
visible in the remote view (shared memory), so a remote thread can execute it
without any cross-process write.
How it works
A section object backs both views with the same physical pages. The local view
is mapped PAGE_READWRITE (to author the shellcode) and the remote view
PAGE_EXECUTE_READ (to run it). Because both descriptors share the section,
memcpy into the local view propagates to the remote process. Execution is
kicked off with a remote thread, a queued APC, or thread hijacking.
NtCreateSection(&hSection, ..., PAGE_EXECUTE_READWRITE, SEC_COMMIT, NULL)
NtMapViewOfSection(hSection, GetCurrentProcess(), &localView, ..., PAGE_READWRITE)
NtMapViewOfSection(hSection, hRemoteProc, &remoteView, ..., PAGE_EXECUTE_READ)
memcpy(localView, shellcode, len) // shared pages — appears in remoteView
CreateRemoteThread(hRemoteProc, NULL, 0, remoteView, arg, 0, NULL)
// or NtQueueApcThread(hThread, remoteView, ...) / thread hijack -> remoteViewDetection & bypass
- Static — The loader imports the native section APIs
NtCreateSection,NtMapViewOfSection, andNtUnmapViewOfSectionfromntdll, but notWriteProcessMemoryand often notVirtualAllocEx. That deliberate absence, paired withNtMapViewOfSectionand a remote-execution primitive (CreateRemoteThread/NtQueueApcThread), is the static signature. - Dynamic — Watch for
NtMapViewOfSectioncalled twice on the same section handle with two different process handles, where the remote mapping is executable (PAGE_EXECUTE_READ) and noWriteProcessMemoryprecedes execution. A cross-process executable section mapping followed byCreateRemoteThread/ APC queue into that view is the key behavioral chain (and Sysmon EID 8 still records the remote thread). - Memory forensics — The injected region is shared (not private) and
executable, image-unbacked. Moneta flags shared
RXregions and unbacked executable shared memory; pe-sieve reports the executable shared mapping that has no disk backing. The same physical pages appearing mapped in two processes is itself anomalous. - Tools — Moneta (shared RX / unbacked exec detection), pe-sieve, Process
Hacker (section objects + region type/protection), API Monitor / ETW
(
NtMapViewOfSectioncalls and handles), Sysmon (EID 8 remote thread), and Volatility (vadinfofor shared executable regions).