ALMC
ALMC Security Logo - Mantenimiento Web, Programación Web Barcelona, Servidores Barcelona, Ciberseguridad Barcelona
  • Online store
  • English
    Español English Français Català

Quick search

Results without leaving the page.

Type to search ALMC products, services, articles and tools.

View all results
Habla a nuestro AgenteIA · respuestas al instante · 24/7
  • HomeALMC
  • ALMCAbout Us
  • ALMC SECURITY S.L.U.Contact
  • Online store
  • Posts
    • All posts
    • Categories
    • Tags
    • Statuses
  • Solutions
    • Desarrollo Web en Lleida — Diseño a Medida que Vende
    • Tienda Online a Medida — E-commerce que Vende de Verdad
    • Chatbot IA para Empresas — Automatiza tu Atención al Cliente
    • Automatización de Procesos para Empresas — Menos Tareas, Más Resultados
    • Desarrollo de Apps Móviles — iOS y Android a Medida
  • Services
    • Cybersecurity
      • Security Audits and Pentesting
      • Monitoring & Incident Response (SIEM)
      • System & Server Hardening
      • Compliance Consulting (GDPR, ENS, ISO 27001)
      • Cloud Security (AWS, Azure, Google Cloud)
    • Programming
      • Full Stack Web Development Laravel, Vue.js
      • Process Automation (Scripts and Bots)
      • Process Automation Scripts and Bots
      • API Integrations & Microservices
      • Code Maintenance and Optimization
    • Servers
      • Server Management & Monitoring
      • Cloud Migration (AWS, Azure, Google Cloud)
      • Performance Optimization
      • Virtualization & Containers (Docker, Kubernetes)
      • Backup & Disaster Recovery Plans
    • Malware Removal
    • Website Maintenance
      • WordPress Maintenance
      • PrestaShop Maintenance
      • Magento Maintenance
      • Joomla Maintenance
      • Drupal Maintenance
      • Shopify Maintenance
      • Wix Maintenance
      • Concrete5 Maintenance
      • HTML Maintenance
      • PHP Maintenance
      • JavaScript Maintenance
      • Python Maintenance
    • Website Repair
      • Hacked site cleanup
      • Fix WordPress
      • Fix PrestaShop
      • Fix Magento
      • Fix Joomla
      • Fix Drupal
      • Fix Shopify
      • Fix OpenCart
      • Fix Moodle
  • Industries
    • 3D Printing & Additive
    • Accounting
    • Advertising & Marketing
    • Aerospace & Defense
    • Agriculture
    • Architecture & Engineering
    • Arts & Culture
    • Automotive
    • Banking & Finance
    • Biomedical Research
    • Biotechnology
    • Breweries
    • Call Centers & BPO
    • Chemicals
    • Cleaning Services
    • Clinics
    • Cloud Providers
    • Construction
    • Consulting
    • Cosmetics & Beauty
    • Courier & Last Mile
    • Cybersecurity
    • Data Centers
    • Defense & Security
    • E-Commerce
    • EdTech
    • Education (K-12)
    • Electrical Equipment
    • Electronics
    • Environmental NGOs
    • Environmental Services
    • Events & Conferences
    • Facilities Management
    • Fashion & Luxury
    • FinTech
    • Fishing & Aquaculture
    • Food & Beverage Manufacturing
    • Forestry
    • Freight Transport
    • Furniture
    • Gaming
    • Government & Public Administration
    • GovTech
    • Gyms & Fitness Centers
    • Healthcare Providers
    • HealthTech
    • Higher Education
    • Home Appliances
    • Home Services
    • Hospitality
    • Hospitals
    • Human Resources
    • Insurance
    • InsurTech
    • Internet & Web Services
    • Investment & Asset Management
    • IT Services
    • Jewelry
    • Landscaping & Gardening
    • Legal Services
    • Logistics & Supply Chain
    • Machinery
    • Maritime
    • Media & Entertainment
    • Medical Devices
    • Metals
    • Mining
    • Music Industry
    • Nonprofit & NGOs
    • Oil & Gas
    • Paper & Print Media
    • Paper & Pulp
    • Pharmaceuticals
    • Photography & Video
    • Plastics
    • Postal & Courier
    • Printing
    • Private Education & Academies
    • Property Development
    • Property Management
    • PropTech
    • Public Safety & Emergency
    • Publishing
    • Rail & Public Transport
    • Real Estate
    • Real Estate Agencies
    • Religious Organizations
    • Renewable Energy
    • Research & Development
    • Research Labs
    • Restaurants & Food Service
    • Retail
    • Security Services
    • Semiconductors
    • Software Development
    • Sports & Fitness
    • Sports Clubs
    • Staffing & Recruitment
    • Telecommunications
    • Textile & Apparel
    • Tobacco
    • Toys
    • Travel & Tourism
    • Travel Agencies
    • Utilities
    • Veterinary & Animal Care
    • Warehousing
    • Waste Management
    • Water Treatment
    • Wholesale
    • Wineries & Vineyards
  • Tools
    • Network
      • What's my IP
      • WHOIS IP
      • Domain WHOIS
      • Geolocate IP
      • DNS Lookup
      • DNS Propagation
      • ASN Lookup
      • Reverse Lookup
      • Domain monitoring
    • Image Compressor
    • MCP Servers
  • Products
    • Whatsboost
      • Whatsboost PrestaShop
      • Whatsboost WordPress
      • Whatsboost Shopify
    • Ulix
      • Extension QR para navegador
    • Chatbot
      • Chatbot WhatsApp
      • Chatbot Instagram
      • Chatbot Facebook
      • Chatbot TikTok
    • VeriFactu
    • Web TV
      • Mis pantallas
      • Vincular nueva TV
      • Dispositivos vinculados
      • Releases APK
      • Pantallas por cliente
    • Control de Fichajes

5 News at ALMC
  • Inauguration of the... Web Maintenance, Web Development Barcelona, Servers Barcelona, Cybersecurity Barcelona
    Inauguration of the...It was a very busy and special day. 30 Jun 2025
  • Website Web Maintenance, Web Development Barcelona, Servers Barcelona, Cybersecurity Barcelona
    WebsiteI recover the domain I had in the past and set up... 01 Jun 2025
  • Signing of the Lease... Web Maintenance, Web Development Barcelona, Servers Barcelona, Cybersecurity Barcelona
    Signing of the Lease...After spending some time looking for premises, my... 01 Jun 2025
  • ALMC returns and com... Web Maintenance, Web Development Barcelona, Servers Barcelona, Cybersecurity Barcelona
    ALMC returns and com...We reactivate the brand with ALMC SECURITY SL (CIF... 23 Apr 2025
  • feb. 2025 Web Maintenance, Web Development Barcelona, Servers Barcelona, Cybersecurity Barcelona
    feb. 2025The decision to start entrepreneurship again was b... 01 Feb 2025

View all news

InjectSetConsole: a stealthier path to remote code injection on Windows

  1. Home
  2. Blog
  3. Categories
  4. Cybersecurity
  5. InjectSetConsole: a stealthier path to remote...
  • All articles
  • Categories
  • Tags
  • Statuses

InjectSetConsole: a stealthier path to remote code injection on Windows

A familiar chain, and why it no longer tells the whole storyFor years, defenders working on Windows environments have learned to recognise a very spec...

A familiar chain, and why it no longer tells the whole story

For years, defenders working on Windows environments have learned to recognise a very specific sequence of API calls: open a handle to a remote process, reserve memory inside it, write a payload, and spawn a thread to run it. That pattern has been the backbone of countless intrusion techniques and, precisely because it is so well known, it is one of the first behaviours that endpoint detection and response tools look for. The problem is that the attackers have read the same documentation. When a detection rule becomes universal, the natural next step is to stop using the primitives that trigger it.

Illustration of data entering a locked process through a legitimate channel while a security camera monitors the path

A recent proof of concept called InjectSetConsole, published by the researcher TwoSevenOneT, illustrates this shift clearly. Instead of writing directly into another process's address space, the technique lets the target process itself receive the data through its standard input and store it in memory. The attacker never calls the memory-writing functions that security products watch so closely. The payload still ends up in the victim's memory, but it gets there through a channel that looks perfectly legitimate.

How the technique works, step by step

The idea is elegant in its simplicity. Rather than forcing data into a remote buffer, the attacker creates an anonymous pipe and launches the target process with its standard input connected to one end of that pipe. The startup information structure redirects stdin, stdout and stderr, so the child process believes it is simply reading from a console or a parent application. From that moment on, there is a fully legitimate input channel available.

Through that pipe, the attacker sends a block of data containing a recognisable marker followed by the content that will later be executed. Because there is no memory allocation call returning a remote address, the injector does not know in advance where those bytes will land. The solution is to search for them afterwards. The PoC uses memory inspection primitives such as VirtualQueryEx and ReadProcessMemory to scan the target process until it finds the marker sequence. Only then does it know the address where the process has stored the data.

There is a second obstacle: that memory is not necessarily executable. The tool queries the region and changes its permissions to allow execution. This is where the technique leaves one of its clearest traces, because a memory region belonging to another process suddenly becomes executable. Finally, instead of creating a new thread, the injector hijacks the main thread of the target and redirects its instruction pointer towards the discovered address. The full chain is reduced to: create a pipe, launch the process with redirected standard input, send controlled data, locate the marker in memory, adjust permissions, and hijack the thread context.

The real lesson: a change of detection surface

The significance of InjectSetConsole is not that it found a magic API to replace the classic memory-writing calls. What matters is that it changes the channel through which data reaches the process memory. In a traditional injection, the attacker writes directly into remote memory. Here, the victim process does part of the work: it receives the data through a pipe and copies it internally. The attacker then simply discovers where it ended up.

This has direct implications for anyone running Windows servers, whether on-premises in a Lleida data centre or in a public cloud region in Barcelona or Frankfurt. A detection strategy based exclusively on the classic trio of allocation, writing and remote thread creation may miss this variant. However, the behavioural chain remains visible: process creation, pipe communication, remote memory inspection, protection changes and thread context manipulation. It is more accurate to talk about a change of detection surface than about complete evasion.

The defensive question should no longer be simply whether a specific function was called. It should be how these bytes appeared in memory, who put them there, and whether the process had any legitimate reason to receive them. That requires correlating events across the endpoint rather than relying on isolated signatures.

What this means for server administrators and hosting providers

For system administrators, hosting companies and SMEs running their own infrastructure, the practical takeaway is that server security cannot depend on a single layer. If an attacker gains a foothold on a Windows server, techniques like this one can make their activity harder to spot with traditional rules. A robust defence combines several measures:

  • Behavioural monitoring: watch for unusual process creation, unexpected pipe usage and memory protection changes, not just known malicious API calls.
  • Least privilege: limit which accounts and services can launch processes or interact with others. Most injection techniques require the attacker to already have a certain level of access.
  • Network-level controls: block or rate-limit connections from IP addresses with a poor reputation. Many intrusions begin with a brute-force attempt or a scan from a known malicious source.
  • Centralised response: when an IP is detected attacking one server, it should be blocked across the entire fleet automatically, without waiting for a human to react.
  • Regular patching and hardening: reduce the attack surface so that even if a technique succeeds, the attacker has fewer places to go.

In this context, tools that centralise protection become especially valuable. ALMC's Abuse Shield, for example, manages fail2ban across multiple machines, blocks malicious IPs automatically and shares an IP reputation feed between all connected servers. If one server in your infrastructure in Girona or Tarragona detects an abusive source, every other server benefits from that knowledge immediately. It is a practical way to close the gap between detection and response, and to make sure that a single compromised entry point does not become a fleet-wide problem.

Conclusion: assume the channel can change

InjectSetConsole is a reminder that attackers adapt to the defences they encounter. The classic injection chain is still used, but it is no longer the only option. Defenders who focus only on the most famous API calls will eventually be surprised by a variant that uses a legitimate pipe, a redirected standard input or a thread hijack instead. The right response is not to panic, but to broaden the view: monitor behaviour, correlate events, harden servers and automate the blocking of malicious sources. In a landscape where the detection surface keeps shifting, layered and centralised protection is no longer a luxury. It is the baseline.

Related

  • How to Harden Your Servers with Fail2ban and IP Reputation Feeds
  • Fail2ban: Your First Line of Defense Against Unauthorized Server Access
  • Critical libssh2 flaw: urgent patch for SSH servers
  • Desarrollo web

Put these ideas into practice

Talk to ALMC about a solution for your business. Explore your options or contact our team.

Soluciones ALMC

Backup & Disaster Recovery Plans
Process Automation Scripts and Bots
Compliance Consulting (GDPR, ENS, ISO 27001)
API Integrations & Microservices
Monitoring & Incident Response (SIEM)
Relacionados
  • Vibe Coding Security: 5 Questions to Ask Before Trusting an AI-Built App
    Cybersecurity · 2 days ago
  • CRA Compliance for Mobile Apps: A 2027 Guide for EU Businesses
    Cybersecurity · 2 days ago
  • Unbound 1.26.1: Critical DNSSEC Flaw and Server Defence
    Cybersecurity · 1 week ago
  • Cisco ISE Zero-Day: Why Patch Now and Harden After
    Cybersecurity · 1 week ago
  • WooCommerce Plugin Flaw: Web Shells and Server Defence
    Cybersecurity · 1 week ago
  • OAuth Token Leak: Supply Chain Lessons for Server Security
    Cybersecurity · 1 week ago
Servidores MCP Destacados
  • Unified Diff MCP Server
    Development
  • Petstore MCP Server & Client
    Development
  • Dooray MCP Server
    Productivity
  • mcp2mqtt
    Communication
  • GraphRAG
    Database
  • Oxylabs
    Web Scraping
  • Markdown Downloader
    Web Scraping
  • Beyond Menu Salesforce MCP
    Cloud Service
  • Bilibili
    Web Scraping
Ver todos los servidores MCP
Cybersecurity · Blog Brain · 2026-09-28
Cerrar panel
Your ecosystem

SaaS applications

Open each workspace directly with your ALMC account.

My account Create account
VeriFactuVerified invoicingAbuse ShieldWeb securityWhatsBoostSales and CRMCommerceStore and POSEmail AISmart emailWebTVDigital signageTime trackingWorking-time controlPrintFlowPrint workflows
Agente Smith · ALMCAgente IA propio on-premise

Hola 👋 Soy Smith, el agente IA de ALMC. Pregúntame sobre ciberseguridad, IA, desarrollo a medida o nuestros productos SaaS.

¿Prefieres hablar con persona? Contacto humano

ALMC access centre

One account · All your services

Start wherever you want.

Create an account to centralise your services, or ask for guidance if you do not know what you need yet.

Create account Talk to ALMC

Explore by product

VeriFactuInvoicingAbuse ShieldSecurityWhatsBoostSalesCommerceStore and POSEmail AIAutomationWebTVDigital signage

Sign in to your account.

The same sign-in brings together your services, team and billing.

Enter my panelAccess your services, team and billing.
Sign in

Not a client yet? Create an account

ALMC Security Logo

Experts in cybersecurity, custom Laravel development, and server management. We deliver robust, secure, and personalized technological solutions.

Latest News

Inauguration of the first office in Lleida of ALMC SECURITY SL
Inauguration of the first office in Lleida of ALMC...
30 Jun 2025
Website
01 Jun 2025
Signing of the Lease Contract
Signing of the Lease Contract
01 Jun 2025

Main Services

  • desarrollo web lleida
  • tienda online a medida
  • chatbot ia empresa
  • automatización procesos empresa
  • desarrollo aplicaciones móviles

SaaS Suite

  • PrintFlow (print shops)
  • WebTV (digital signage)
  • VeriFactu (invoicing)
  • Time tracking

Contact

  • Rambla de Ferran, 37, 25007 Lleida

  • +34 614 443 757

  • info@almc.es

Follow Us

Useful links

  • About us
  • Contact
  • Reserva cita
  • Hacked website repair
  • Website maintenance
  • Website repair
  • Tools
  • What is my IP
  • Compress images
  • Site search
  • Blog

© Copyright 2026. ALMC SECURITY S.L.U.

  • Legal
      • Privacy Policy
      • Terms and Conditions of Service
      • Legal Notice and Corporate Information
      • Cookie Policy
  • Resources
    • Blog
    • Sitemap

ALMC

Legal

This site only uses first-party cookies and local browser storage, and only to make it work: keeping your session, protecting forms, remembering your language and not showing you this notice again. We use no analytics or advertising cookies, there are no third-party cookies and we do not build profiles. As strictly necessary technical cookies, they are exempt from consent under Article 22.2 of the Spanish LSSI-CE: this notice is informative and the button only stops it from appearing again. You can delete or block them from your browser, though some features may then stop working. Cookie Policy · Privacy Policy.

Chat now
Call Sales
+34 614 443 757

More ways to contact us

Shall we talk directly?

Book an appointment in my calendar — I will call you or we can meet via Google Meet

  • ✓Instant confirmation via WhatsApp
  • ✓Real-time availability
  • ✓Reminder 1 hour before
  • ✓Cancel or reschedule with a single click
Initial consultation · 30min
📅 Check availability and book