Skip to content

Section Mapping Injection

Injecting code without WriteProcessMemory by mapping a shared section into both the local and remote process, writing shellcode through the local view, then executing it from the remote view.

Section mapping injection delivers a payload into a remote process without ever calling WriteProcessMemory, defeating the most heavily monitored injection API. The attacker creates a memory-backed section object and maps two views of it: a read/write view in the local process and a read/execute view in the remote process. Shellcode written through the local view is immediately visible in the remote view (shared memory), so a remote thread can execute it without any cross-process write.

How it works

A section object backs both views with the same physical pages. The local view is mapped PAGE_READWRITE (to author the shellcode) and the remote view PAGE_EXECUTE_READ (to run it). Because both descriptors share the section, memcpy into the local view propagates to the remote process. Execution is kicked off with a remote thread, a queued APC, or thread hijacking.

text
NtCreateSection(&hSection, ..., PAGE_EXECUTE_READWRITE, SEC_COMMIT, NULL)
NtMapViewOfSection(hSection, GetCurrentProcess(), &localView, ..., PAGE_READWRITE)
NtMapViewOfSection(hSection, hRemoteProc, &remoteView, ..., PAGE_EXECUTE_READ)
memcpy(localView, shellcode, len)            // shared pages — appears in remoteView
CreateRemoteThread(hRemoteProc, NULL, 0, remoteView, arg, 0, NULL)
// or NtQueueApcThread(hThread, remoteView, ...) / thread hijack -> remoteView

Detection & bypass

  • Static — The loader imports the native section APIs NtCreateSection, NtMapViewOfSection, and NtUnmapViewOfSection from ntdll, but not WriteProcessMemory and often not VirtualAllocEx. That deliberate absence, paired with NtMapViewOfSection and a remote-execution primitive (CreateRemoteThread/NtQueueApcThread), is the static signature.
  • Dynamic — Watch for NtMapViewOfSection called twice on the same section handle with two different process handles, where the remote mapping is executable (PAGE_EXECUTE_READ) and no WriteProcessMemory precedes execution. A cross-process executable section mapping followed by CreateRemoteThread / APC queue into that view is the key behavioral chain (and Sysmon EID 8 still records the remote thread).
  • Memory forensics — The injected region is shared (not private) and executable, image-unbacked. Moneta flags shared RX regions and unbacked executable shared memory; pe-sieve reports the executable shared mapping that has no disk backing. The same physical pages appearing mapped in two processes is itself anomalous.
  • Tools — Moneta (shared RX / unbacked exec detection), pe-sieve, Process Hacker (section objects + region type/protection), API Monitor / ETW (NtMapViewOfSection calls and handles), Sysmon (EID 8 remote thread), and Volatility (vadinfo for shared executable regions).
Votes

Comments(0)