Thread context manipulation from exception handler
Identifies attempts to manipulate thread context from inside the exception handler. Attackers can hijack execution as part of stealthy process injection or patchless AMSI bypass techniques.
- Platform: Windows
- Severity: High
- MITRE Tactic: Defense Evasion
- MITRE Techniques: T1055