What MITRE ATT&CK T1055.011: Extra Window Memory Injection (Enterprise Tactic TA0005 - Defense Evasion / TA0004 - Privilege Escalation) requires
MITRE ATT&CK T1055.011 (Extra Window Memory Injection) is an Enterprise Defense Evasion and Privilege Escalation sub-technique of T1055 (Process Injection). Adversaries may inject malicious code into process via Extra Window Memory (EWM) in order to evade process-based defenses as well as possibly elevate privileges. EWM injection is a method of executing arbitrary code in the address space of a separate live process. Before creating a window, graphical Windows-based processes must prescribe to or register a windows class, which stipulate appearance and behavior (via windows procedures, which are functions that handle input/output of data). Affected platforms: Windows. MITRE-documented mitigations include M1040 Behavior Prevention on Endpoint. The Center for Threat-Informed Defense maps this technique to NIST SP 800-53 Rev 5 controls AC-02, AC-03, AC-05, AC-06, CM-05, CM-06, IA-02, SC-07.
Pillar: Cybersecurity · Authority: MITRE Corporation · Version: 1.0.0 · Last updated:
Primary source: https://attack.mitre.org/techniques/T1055/011/
SHA-256 integrity: 99578fc44545bf02b11bc84c35237a88cb84dc28b234bfc250a9b1dfae7494b2
Primary Citations — 7 traced to source
- MITRE ATT&CK Technique T1055.011: Extra Window Memory Injection (https://attack.mitre.org/techniques/T1055/011/)
- MITRE ATT&CK Tactic TA0005: Defense Evasion (https://attack.mitre.org/tactics/TA0005/)
+ 5 more citations (full bibliography, deterministic workflow, actionable schema and crosswalks) included in the vault unlock — $0.01 via Skyfire / L402 / Direct Base USDC.
Access
- Discovery (free): /api/v1/nodes/mitre-attack-t1055-011-extra-window-memory-injection.json — 6-field metadata
- Vault (full node): /api/v1/vault/nodes/mitre-attack-t1055-011-extra-window-memory-injection.json — full 13-key payload, $0.01 USDC (L402/Skyfire/Direct Base)
- Canonical URL: https://bidda.com/intelligence/mitre-attack-t1055-011-extra-window-memory-injection
- Back to registry: Browse all 10,085 compliance nodes