A new technique revealed by security researcher Two Seven One Three circumvents two key APIs used in remote code injection: VirtualAllocEx and WriteProcessMemory. This method, dubbed console named-pipe injection, leverages a child console process's redirected standard input to deliver payload bytes. It repurposes pre-existing memory Windows has already allocated, effectively sidestepping common detection mechanisms that rely on the familiar allocate-write-execute sequence.
This behavior is tracked by MITRE ATT&CK as T1055, and conventional implementations often open or create a target process, allocate remote memory, copy code with WriteProcessMemory, and start or hijack a thread. Payloads need to avoid carriage return, line feed, and Ctrl+Z substitute bytes due to potential console parsing issues.
SensePost's Max Hirschberger and Ogulcan Ugur claimed their separate technique bypassed four leading EDR products, but this does not validate the newer implementation. Key indicators include an unusual parent launching an interactive console binary with redirected handles, binary-like standard-input writes, memory scanning, a remote VirtualProtectEx transition to executable permissions, and SetThreadContext followed by resumption. Sysmon Event IDs 17 and 18 offer named-pipe telemetry, though anonymous standard-input pipes may require enhanced endpoint and handle-level visibility.
Security teams should establish baselines for console automation and seek out rare combinations rather than flagging every conhost.exe, nslookup.exe, or pipe operation. Research highlights an important lesson for crafting tools that detect harmful process injections.










