Custom Userland Primitives: Detect the Invariants
Custom implementations are designed to escape labels and public signatures. Defenders can remain effective by decomposing injection into required capabilities: obtain access, place or modify code or control data, trigger execution, and produce an observable effect.
This taxonomy supports threat hunting and detection engineering. It excludes implementation code, undocumented structure recipes, and advice for reducing security visibility.
A primitive-based model
Technique names combine mechanisms into familiar recipes. A primitive model separates them. Access might involve process, thread, section, or synchronization objects. Placement can mean new private memory, a shared section, changed image pages, or modified callback data. A trigger may involve a thread, APC, callback, work queue, exception, or hijacked control flow. Effects include child processes, file access, credentials, persistence, and network communication.
Telemetry matrix
- Access: source/target process, token, signer, requested rights, handle lineage, session, and integrity level.
- Placement: allocation type, section provenance, page-protection history, writer, bytes, and file backing.
- Trigger: thread origin, APC or callback metadata, queue state, instruction pointer, and stack.
- Effects: process tree, identity use, files, registry, services, named objects, DNS, and network.
Create analytics that tolerate one missing stage but demand corroboration from another. For example, an unknown callback plus private executable memory and a rare source-target handle relationship is stronger than an API-name alert.
Hunting and response
Start from high-confidence effects or high-value target access, pivot to memory and handles, then reconstruct the trigger. Preserve raw events so new hypotheses can be tested later. Cluster incidents by code similarity, infrastructure, signer, parentage, and memory traits without assuming that identical primitives mean identical actors.
GitHub tools and safe testing
capa, Volatility 3, PE-sieve, Moneta, and Sigma support capability analysis, memory validation, and portable detection logic. Test with synthetic event chains and approved commercial instrumentation products that exercise legitimate cross-process behavior. Avoid building a custom injector merely to test a detector.
ATT&CK, CVEs, and controls
Map to the most specific T1055 sub-technique supported by evidence; otherwise retain T1055 and document the observed primitives. Custom userland code is not a CVE. Exploitation used to gain the necessary rights is a separate finding. Layer WDAC, least privilege, ASR, credential isolation, EDR tamper protection, memory telemetry, and segmentation so a novel trigger still meets several independent controls.