Skip to content
New EDR Evasion Technique: Process Parameter Poisoning

New EDR Evasion Technique: Process Parameter Poisoning

First seen 22 Sep 2026, 21:58 UTC

Article Content

Browse articles
ThreatCluster AI
ThreatCluster September 22, 2026 at 22:55 UTC
  • Process Parameter Poisoning bypasses traditional EDR detection methods.
  • The technique successfully evaded alerts in four leading EDR products.
  • Proof-of-concept code for the technique is publicly available on GitHub.

Researchers Max Hirschberger and Ogulcan Ugur have developed a novel attack technique called Process Parameter Poisoning, which allows code injection into foreign processes without triggering detection by leading Endpoint Detection and Response (EDR) solutions. This method successfully bypassed alerts in four major EDR products during testing. The technique avoids traditional memory-accessing APIs like WriteProcessMemory and VirtualAllocEx, which are heavily monitored by security tools. Instead, it exploits process startup parameters to inject malicious code, significantly enhancing evasion capabilities. The proof-of-concept implementation is available on GitHub, and the technique poses a substantial risk to organizations relying on conventional EDR solutions. The current status indicates that this technique is validated and poses a serious threat to endpoint security.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated just now How this analysis works

Timeline

2026-09-22
Process Parameter Poisoning disclosed
Max Hirschberger and Ogulcan Ugur published a novel EDR evasion technique that bypasses detection mechanisms.
Flashpoint
2026-09-22
Testing against EDR solutions
The technique was tested against four market-leading EDR solutions, achieving zero alerts.
sensepost.com

More articles in this cluster (6)