research
Published 2026-09-27
Verified 2026-09-28

Windows console named-pipe injection (Two Seven One Three, 26 Sep / CSN 27 Sep): payload via redirected stdin — skips VirtualAllocEx + WriteProcessMemory

Researcher Two Seven One Three (Zero Salarium, 26 September 2026; amplified Cybersecurity News / talkback 27 Sep) documents a Windows process-injection technique that avoids VirtualAllocEx and WriteProcessMemory commonly correlated by EDR. Console named-pipe injection: CreateProcess launches an interactive console child (e.g. nslookup.exe / netsh.exe) with redirected hStdInput; WriteFile delivers payload bytes (avoiding console bad chars 0x0D/0x0A/0x1A) into memory the console already holds; a distinctive marker locates the buffer; VirtualProtectEx flips existing pages executable; a thread RIP is retargeted past the marker (MITRE ATT&CK T1055). Notes related prior work by SensePost (Hirschberger/Ugur) and modexp but avoids suspended-init / unusual lpCommandLine patterns. Research / PoC — no CVE. Defenders: do not treat absence of WriteProcessMemory alone as absence of injection; watch console-child creation with redirected handles, cross-process VirtualProtectEx, named-pipe stdin writes, and unusual thread-context changes. Primary: researcher post; wire: CSN.

Product
Microsoft Windows (process injection / console + named-pipe stdin path)
Versions
n/a (technique research; applies where console children accept redirected stdin and cross-process VirtualProtectEx / thread context APIs are available)
Exploited in Australia?
unknown
Patch to
No vendor patch — detection engineering: alert on console utilities spawned with redirected stdin pipes, cross-process VirtualProtectEx without preceding WriteProcessMemory, and thread suspend/set-context/resume chains; validate EDR coverage beyond VirtualAllocEx/WriteProcessMemory signatures

Primary: Zero Salarium — EDR evasion: process injection without WriteProcessMemory (Two Seven One Three; 26 Sep 2026) · Vendor: Cybersecurity News — console named-pipe injection / EDR evasion (27 Sep 2026) · MITRE ATT&CK — T1055 Process Injection

tech identity