{"id":8661,"date":"2024-01-04T08:18:31","date_gmt":"2024-01-04T08:18:31","guid":{"rendered":"https:\/\/sekuritasit.com\/index.php\/2024\/01\/04\/fortiedr-coverage-poolparty-code-injection-technique\/"},"modified":"2024-01-04T08:18:31","modified_gmt":"2024-01-04T08:18:31","slug":"fortiedr-coverage-poolparty-code-injection-technique","status":"publish","type":"post","link":"https:\/\/sekuritasit.com\/index.php\/2024\/01\/04\/fortiedr-coverage-poolparty-code-injection-technique\/","title":{"rendered":"FortiEDR coverage: PoolParty Code Injection Technique"},"content":{"rendered":"<p>What is the Attack?<\/p>\n<p>On December 6, researchers from SafeBreach published a new code injection technique for Windows OS called &#8220;Pool Party&#8221; in the Blackhat EU briefing.<\/p>\n<p>The &#8220;Pool Party&#8221; technique allows injecting processes using the WINAPI thread pool and relies on the fact that every process has an automatically enabled thread pool. It then uses the API on the target process to add new routines to the existing thread pool. <\/p>\n<p>Why is this Significant?<\/p>\n<p>The new injection technique implements eight different variants. These have been tested by SafeBreach researchers against 5 leading EDR products and reported to be effective in evading them.<\/p>\n<p>Currently, no threat actors have been identified using this technique.<\/p>\n<p>What is the Status of Coverage?<\/p>\n<p>FortiEDR blocks all PoolParty variants out of the box. <\/p>\n<p>FortiEDR&#8217;s injection detection does not rely on a specific API being called, but rather on a kernel behavior detection policy that allows unknown techniques to be detected.<\/p>\n<p>Malicious actions by the injected threads, such as attempting to connect to C2, will be blocked by EDR.<\/p>\n<p>FortiEDR customers with Collector versions 5.2.0 and 5.2.2 are protected with no update required to Collector or Content.<a href=\"https:\/\/fortiguard.fortinet.com\/threat-signal-report\/5357\" target=\"_blank\" class=\"feedzy-rss-link-icon\" rel=\"noopener\">Read More<\/a>\u00a0<\/p>","protected":false},"excerpt":{"rendered":"<p>What is the Attack? On December 6, researchers from SafeBreach published a new code injection technique for Windows OS called &#8220;Pool Party&#8221; in the Blackhat EU briefing. The &#8220;Pool Party&#8221; technique allows injecting processes using the WINAPI thread pool and relies on the fact that every process has an automatically enabled thread pool. It then [&hellip;]<\/p>\n","protected":false},"author":0,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"om_disable_all_campaigns":false,"_monsterinsights_skip_tracking":false,"_monsterinsights_sitenote_active":false,"_monsterinsights_sitenote_note":"","_monsterinsights_sitenote_category":0,"footnotes":""},"categories":[1],"tags":[],"class_list":["post-8661","post","type-post","status-publish","format-standard","hentry","category-uncategorized"],"aioseo_notices":[],"aioseo_head":"\n\t\t<!-- All in One SEO 4.9.8 - aioseo.com -->\n\t<meta name=\"description\" content=\"What is the Attack? On December 6, researchers from SafeBreach published a new code injection technique for Windows OS called &quot;Pool Party&quot; in the Blackhat EU briefing. The &quot;Pool Party&quot; technique allows injecting processes using the WINAPI thread pool and relies on the fact that every process has an automatically enabled thread pool. It then\" \/>\n\t<meta name=\"robots\" content=\"max-image-preview:large\" \/>\n\t<link rel=\"canonical\" href=\"https:\/\/sekuritasit.com\/index.php\/2024\/01\/04\/fortiedr-coverage-poolparty-code-injection-technique\/\" \/>\n\t<meta name=\"generator\" content=\"All in One SEO (AIOSEO) 4.9.8\" \/>\n\t\t<meta property=\"og:locale\" content=\"en_US\" \/>\n\t\t<meta property=\"og:site_name\" content=\"Sekuritas IT \u203a Creative solutions to unique challenges.\" \/>\n\t\t<meta property=\"og:type\" content=\"article\" \/>\n\t\t<meta property=\"og:title\" content=\"FortiEDR coverage: PoolParty Code Injection Technique \u203a Sekuritas IT\" \/>\n\t\t<meta property=\"og:description\" content=\"What is the Attack? On December 6, researchers from SafeBreach published a new code injection technique for Windows OS called &quot;Pool Party&quot; in the Blackhat EU briefing. The &quot;Pool Party&quot; technique allows injecting processes using the WINAPI thread pool and relies on the fact that every process has an automatically enabled thread pool. It then\" \/>\n\t\t<meta property=\"og:url\" content=\"https:\/\/sekuritasit.com\/index.php\/2024\/01\/04\/fortiedr-coverage-poolparty-code-injection-technique\/\" \/>\n\t\t<meta property=\"article:published_time\" content=\"2024-01-04T08:18:31+00:00\" \/>\n\t\t<meta property=\"article:modified_time\" content=\"2024-01-04T08:18:31+00:00\" \/>\n\t\t<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/profile.php?id=100086973577423\" \/>\n\t\t<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n\t\t<meta name=\"twitter:title\" content=\"FortiEDR coverage: PoolParty Code Injection Technique \u203a Sekuritas IT\" \/>\n\t\t<meta name=\"twitter:description\" content=\"What is the Attack? On December 6, researchers from SafeBreach published a new code injection technique for Windows OS called &quot;Pool Party&quot; in the Blackhat EU briefing. The &quot;Pool Party&quot; technique allows injecting processes using the WINAPI thread pool and relies on the fact that every process has an automatically enabled thread pool. It then\" \/>\n\t\t<script type=\"application\/ld+json\" class=\"aioseo-schema\">\n\t\t\t{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"BlogPosting\",\"@id\":\"https:\\\/\\\/sekuritasit.com\\\/index.php\\\/2024\\\/01\\\/04\\\/fortiedr-coverage-poolparty-code-injection-technique\\\/#blogposting\",\"name\":\"FortiEDR coverage: PoolParty Code Injection Technique \\u203a Sekuritas IT\",\"headline\":\"FortiEDR coverage: PoolParty Code Injection Technique\",\"author\":{\"@id\":\"https:\\\/\\\/sekuritasit.com\\\/index.php\\\/author\\\/#author\"},\"publisher\":{\"@id\":\"https:\\\/\\\/sekuritasit.com\\\/#organization\"},\"datePublished\":\"2024-01-04T08:18:31+00:00\",\"dateModified\":\"2024-01-04T08:18:31+00:00\",\"inLanguage\":\"en-US\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/sekuritasit.com\\\/index.php\\\/2024\\\/01\\\/04\\\/fortiedr-coverage-poolparty-code-injection-technique\\\/#webpage\"},\"isPartOf\":{\"@id\":\"https:\\\/\\\/sekuritasit.com\\\/index.php\\\/2024\\\/01\\\/04\\\/fortiedr-coverage-poolparty-code-injection-technique\\\/#webpage\"},\"articleSection\":\"Uncategorized\"},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/sekuritasit.com\\\/index.php\\\/2024\\\/01\\\/04\\\/fortiedr-coverage-poolparty-code-injection-technique\\\/#breadcrumblist\",\"itemListElement\":[{\"@type\":\"ListItem\",\"@id\":\"https:\\\/\\\/sekuritasit.com#listItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/sekuritasit.com\",\"nextItem\":{\"@type\":\"ListItem\",\"@id\":\"https:\\\/\\\/sekuritasit.com\\\/index.php\\\/category\\\/uncategorized\\\/#listItem\",\"name\":\"Uncategorized\"}},{\"@type\":\"ListItem\",\"@id\":\"https:\\\/\\\/sekuritasit.com\\\/index.php\\\/category\\\/uncategorized\\\/#listItem\",\"position\":2,\"name\":\"Uncategorized\",\"item\":\"https:\\\/\\\/sekuritasit.com\\\/index.php\\\/category\\\/uncategorized\\\/\",\"nextItem\":{\"@type\":\"ListItem\",\"@id\":\"https:\\\/\\\/sekuritasit.com\\\/index.php\\\/2024\\\/01\\\/04\\\/fortiedr-coverage-poolparty-code-injection-technique\\\/#listItem\",\"name\":\"FortiEDR coverage: PoolParty Code Injection Technique\"},\"previousItem\":{\"@type\":\"ListItem\",\"@id\":\"https:\\\/\\\/sekuritasit.com#listItem\",\"name\":\"Home\"}},{\"@type\":\"ListItem\",\"@id\":\"https:\\\/\\\/sekuritasit.com\\\/index.php\\\/2024\\\/01\\\/04\\\/fortiedr-coverage-poolparty-code-injection-technique\\\/#listItem\",\"position\":3,\"name\":\"FortiEDR coverage: PoolParty Code Injection Technique\",\"previousItem\":{\"@type\":\"ListItem\",\"@id\":\"https:\\\/\\\/sekuritasit.com\\\/index.php\\\/category\\\/uncategorized\\\/#listItem\",\"name\":\"Uncategorized\"}}]},{\"@type\":\"Organization\",\"@id\":\"https:\\\/\\\/sekuritasit.com\\\/#organization\",\"name\":\"Sekuritas IT\",\"description\":\"Creative solutions to unique challenges.\",\"url\":\"https:\\\/\\\/sekuritasit.com\\\/\",\"sameAs\":[\"https:\\\/\\\/www.facebook.com\\\/profile.php?id=100086973577423\"]},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/sekuritasit.com\\\/index.php\\\/2024\\\/01\\\/04\\\/fortiedr-coverage-poolparty-code-injection-technique\\\/#webpage\",\"url\":\"https:\\\/\\\/sekuritasit.com\\\/index.php\\\/2024\\\/01\\\/04\\\/fortiedr-coverage-poolparty-code-injection-technique\\\/\",\"name\":\"FortiEDR coverage: PoolParty Code Injection Technique \\u203a Sekuritas IT\",\"description\":\"What is the Attack? On December 6, researchers from SafeBreach published a new code injection technique for Windows OS called \\\"Pool Party\\\" in the Blackhat EU briefing. The \\\"Pool Party\\\" technique allows injecting processes using the WINAPI thread pool and relies on the fact that every process has an automatically enabled thread pool. It then\",\"inLanguage\":\"en-US\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/sekuritasit.com\\\/#website\"},\"breadcrumb\":{\"@id\":\"https:\\\/\\\/sekuritasit.com\\\/index.php\\\/2024\\\/01\\\/04\\\/fortiedr-coverage-poolparty-code-injection-technique\\\/#breadcrumblist\"},\"author\":{\"@id\":\"https:\\\/\\\/sekuritasit.com\\\/index.php\\\/author\\\/#author\"},\"creator\":{\"@id\":\"https:\\\/\\\/sekuritasit.com\\\/index.php\\\/author\\\/#author\"},\"datePublished\":\"2024-01-04T08:18:31+00:00\",\"dateModified\":\"2024-01-04T08:18:31+00:00\"},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/sekuritasit.com\\\/#website\",\"url\":\"https:\\\/\\\/sekuritasit.com\\\/\",\"name\":\"Sekuritas IT\",\"alternateName\":\"Sekuritas\",\"description\":\"Creative solutions to unique challenges.\",\"inLanguage\":\"en-US\",\"publisher\":{\"@id\":\"https:\\\/\\\/sekuritasit.com\\\/#organization\"}}]}\n\t\t<\/script>\n\t\t<!-- All in One SEO -->\n\n","aioseo_head_json":{"title":"FortiEDR coverage: PoolParty Code Injection Technique \u203a Sekuritas IT","description":"What is the Attack? On December 6, researchers from SafeBreach published a new code injection technique for Windows OS called \"Pool Party\" in the Blackhat EU briefing. The \"Pool Party\" technique allows injecting processes using the WINAPI thread pool and relies on the fact that every process has an automatically enabled thread pool. It then","canonical_url":"https:\/\/sekuritasit.com\/index.php\/2024\/01\/04\/fortiedr-coverage-poolparty-code-injection-technique\/","robots":"max-image-preview:large","keywords":"","webmasterTools":{"miscellaneous":""},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"BlogPosting","@id":"https:\/\/sekuritasit.com\/index.php\/2024\/01\/04\/fortiedr-coverage-poolparty-code-injection-technique\/#blogposting","name":"FortiEDR coverage: PoolParty Code Injection Technique \u203a Sekuritas IT","headline":"FortiEDR coverage: PoolParty Code Injection Technique","author":{"@id":"https:\/\/sekuritasit.com\/index.php\/author\/#author"},"publisher":{"@id":"https:\/\/sekuritasit.com\/#organization"},"datePublished":"2024-01-04T08:18:31+00:00","dateModified":"2024-01-04T08:18:31+00:00","inLanguage":"en-US","mainEntityOfPage":{"@id":"https:\/\/sekuritasit.com\/index.php\/2024\/01\/04\/fortiedr-coverage-poolparty-code-injection-technique\/#webpage"},"isPartOf":{"@id":"https:\/\/sekuritasit.com\/index.php\/2024\/01\/04\/fortiedr-coverage-poolparty-code-injection-technique\/#webpage"},"articleSection":"Uncategorized"},{"@type":"BreadcrumbList","@id":"https:\/\/sekuritasit.com\/index.php\/2024\/01\/04\/fortiedr-coverage-poolparty-code-injection-technique\/#breadcrumblist","itemListElement":[{"@type":"ListItem","@id":"https:\/\/sekuritasit.com#listItem","position":1,"name":"Home","item":"https:\/\/sekuritasit.com","nextItem":{"@type":"ListItem","@id":"https:\/\/sekuritasit.com\/index.php\/category\/uncategorized\/#listItem","name":"Uncategorized"}},{"@type":"ListItem","@id":"https:\/\/sekuritasit.com\/index.php\/category\/uncategorized\/#listItem","position":2,"name":"Uncategorized","item":"https:\/\/sekuritasit.com\/index.php\/category\/uncategorized\/","nextItem":{"@type":"ListItem","@id":"https:\/\/sekuritasit.com\/index.php\/2024\/01\/04\/fortiedr-coverage-poolparty-code-injection-technique\/#listItem","name":"FortiEDR coverage: PoolParty Code Injection Technique"},"previousItem":{"@type":"ListItem","@id":"https:\/\/sekuritasit.com#listItem","name":"Home"}},{"@type":"ListItem","@id":"https:\/\/sekuritasit.com\/index.php\/2024\/01\/04\/fortiedr-coverage-poolparty-code-injection-technique\/#listItem","position":3,"name":"FortiEDR coverage: PoolParty Code Injection Technique","previousItem":{"@type":"ListItem","@id":"https:\/\/sekuritasit.com\/index.php\/category\/uncategorized\/#listItem","name":"Uncategorized"}}]},{"@type":"Organization","@id":"https:\/\/sekuritasit.com\/#organization","name":"Sekuritas IT","description":"Creative solutions to unique challenges.","url":"https:\/\/sekuritasit.com\/","sameAs":["https:\/\/www.facebook.com\/profile.php?id=100086973577423"]},{"@type":"WebPage","@id":"https:\/\/sekuritasit.com\/index.php\/2024\/01\/04\/fortiedr-coverage-poolparty-code-injection-technique\/#webpage","url":"https:\/\/sekuritasit.com\/index.php\/2024\/01\/04\/fortiedr-coverage-poolparty-code-injection-technique\/","name":"FortiEDR coverage: PoolParty Code Injection Technique \u203a Sekuritas IT","description":"What is the Attack? On December 6, researchers from SafeBreach published a new code injection technique for Windows OS called \"Pool Party\" in the Blackhat EU briefing. The \"Pool Party\" technique allows injecting processes using the WINAPI thread pool and relies on the fact that every process has an automatically enabled thread pool. It then","inLanguage":"en-US","isPartOf":{"@id":"https:\/\/sekuritasit.com\/#website"},"breadcrumb":{"@id":"https:\/\/sekuritasit.com\/index.php\/2024\/01\/04\/fortiedr-coverage-poolparty-code-injection-technique\/#breadcrumblist"},"author":{"@id":"https:\/\/sekuritasit.com\/index.php\/author\/#author"},"creator":{"@id":"https:\/\/sekuritasit.com\/index.php\/author\/#author"},"datePublished":"2024-01-04T08:18:31+00:00","dateModified":"2024-01-04T08:18:31+00:00"},{"@type":"WebSite","@id":"https:\/\/sekuritasit.com\/#website","url":"https:\/\/sekuritasit.com\/","name":"Sekuritas IT","alternateName":"Sekuritas","description":"Creative solutions to unique challenges.","inLanguage":"en-US","publisher":{"@id":"https:\/\/sekuritasit.com\/#organization"}}]},"og:locale":"en_US","og:site_name":"Sekuritas IT \u203a Creative solutions to unique challenges.","og:type":"article","og:title":"FortiEDR coverage: PoolParty Code Injection Technique \u203a Sekuritas IT","og:description":"What is the Attack? On December 6, researchers from SafeBreach published a new code injection technique for Windows OS called &quot;Pool Party&quot; in the Blackhat EU briefing. The &quot;Pool Party&quot; technique allows injecting processes using the WINAPI thread pool and relies on the fact that every process has an automatically enabled thread pool. It then","og:url":"https:\/\/sekuritasit.com\/index.php\/2024\/01\/04\/fortiedr-coverage-poolparty-code-injection-technique\/","article:published_time":"2024-01-04T08:18:31+00:00","article:modified_time":"2024-01-04T08:18:31+00:00","article:publisher":"https:\/\/www.facebook.com\/profile.php?id=100086973577423","twitter:card":"summary_large_image","twitter:title":"FortiEDR coverage: PoolParty Code Injection Technique \u203a Sekuritas IT","twitter:description":"What is the Attack? On December 6, researchers from SafeBreach published a new code injection technique for Windows OS called &quot;Pool Party&quot; in the Blackhat EU briefing. The &quot;Pool Party&quot; technique allows injecting processes using the WINAPI thread pool and relies on the fact that every process has an automatically enabled thread pool. It then"},"aioseo_meta_data":{"post_id":"8661","title":null,"description":null,"keywords":null,"keyphrases":null,"primary_term":null,"canonical_url":null,"og_title":null,"og_description":null,"og_object_type":"default","og_image_type":"default","og_image_url":null,"og_image_width":null,"og_image_height":null,"og_image_custom_url":null,"og_image_custom_fields":null,"og_video":null,"og_custom_url":null,"og_article_section":null,"og_article_tags":null,"twitter_use_og":false,"twitter_card":"default","twitter_image_type":"default","twitter_image_url":null,"twitter_image_custom_url":null,"twitter_image_custom_fields":null,"twitter_title":null,"twitter_description":null,"schema":{"blockGraphs":[],"customGraphs":[],"default":{"data":{"Article":[],"Course":[],"Dataset":[],"FAQPage":[],"Movie":[],"Person":[],"Product":[],"ProductReview":[],"Car":[],"Recipe":[],"Service":[],"SoftwareApplication":[],"WebPage":[]},"graphName":"","isEnabled":true},"graphs":[]},"schema_type":"default","schema_type_options":null,"pillar_content":false,"robots_default":true,"robots_noindex":false,"robots_noarchive":false,"robots_nosnippet":false,"robots_nofollow":false,"robots_noimageindex":false,"robots_noodp":false,"robots_notranslate":false,"robots_max_snippet":null,"robots_max_videopreview":null,"robots_max_imagepreview":"large","priority":null,"frequency":null,"local_seo":null,"breadcrumb_settings":null,"limit_modified_date":false,"ai":null,"created":"2024-01-04 11:55:15","updated":"2025-10-15 06:30:10","seo_analyzer_scan_date":null},"aioseo_breadcrumb":"<div class=\"aioseo-breadcrumbs\"><span class=\"aioseo-breadcrumb\">\n\t\t\t<a href=\"https:\/\/sekuritasit.com\" title=\"Home\">Home<\/a>\n\t\t<\/span><span class=\"aioseo-breadcrumb-separator\">&raquo;<\/span><span class=\"aioseo-breadcrumb\">\n\t\t\t<a href=\"https:\/\/sekuritasit.com\/index.php\/category\/uncategorized\/\" title=\"Uncategorized\">Uncategorized<\/a>\n\t\t<\/span><span class=\"aioseo-breadcrumb-separator\">&raquo;<\/span><span class=\"aioseo-breadcrumb\">\n\t\t\tFortiEDR coverage: PoolParty Code Injection Technique\n\t\t<\/span><\/div>","aioseo_breadcrumb_json":[{"label":"Home","link":"https:\/\/sekuritasit.com"},{"label":"Uncategorized","link":"https:\/\/sekuritasit.com\/index.php\/category\/uncategorized\/"},{"label":"FortiEDR coverage: PoolParty Code Injection Technique","link":"https:\/\/sekuritasit.com\/index.php\/2024\/01\/04\/fortiedr-coverage-poolparty-code-injection-technique\/"}],"_links":{"self":[{"href":"https:\/\/sekuritasit.com\/index.php\/wp-json\/wp\/v2\/posts\/8661","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/sekuritasit.com\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/sekuritasit.com\/index.php\/wp-json\/wp\/v2\/types\/post"}],"replies":[{"embeddable":true,"href":"https:\/\/sekuritasit.com\/index.php\/wp-json\/wp\/v2\/comments?post=8661"}],"version-history":[{"count":0,"href":"https:\/\/sekuritasit.com\/index.php\/wp-json\/wp\/v2\/posts\/8661\/revisions"}],"wp:attachment":[{"href":"https:\/\/sekuritasit.com\/index.php\/wp-json\/wp\/v2\/media?parent=8661"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/sekuritasit.com\/index.php\/wp-json\/wp\/v2\/categories?post=8661"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/sekuritasit.com\/index.php\/wp-json\/wp\/v2\/tags?post=8661"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}