Publicly-reported instances of Process Injection bypassing endpoint security products. Maintained on the same basis for every technique in the Index.
| Product | Entries | High-confidence | Most recent |
|---|---|---|---|
| Microsoft | 6 | 4 | 2025-08-14 |
| CrowdStrike | 2 | 2 | 2025-03-05 |
| 1 | 1 | 2025-08-14 | |
| Palo Alto | 1 | 1 | 2023-12-08 |
| Pearson | 1 | 1 | 2024-06-18 |
| Respondus | 1 | 1 | 2025-07-24 |
| SentinelOne | 1 | 1 | 2023-12-08 |
| Skyhigh Security | 1 | 1 | 2024-10-29 |
| STRANGETRINITY | 1 | 1 | 2023-08-03 |
| TN ROM (HyperTN/MIUITN) | 1 | 1 | 2025-11-05 |
| Brave | 1 | 1 | 2025-08-14 |
| Trellix | 1 | 0 | 2024-10-29 |
| Cybereason | 1 | 1 | 2023-12-08 |
| Product | Confidence | Disclosed | Source | |
|---|---|---|---|---|
| TN ROM (HyperTN/MIUITN) | high | 2025-11-05 | github.com | record → |
| Brave | high | 2025-08-14 | github.com | record → |
| Microsoft | high | 2025-08-14 | github.com | record → |
| high | 2025-08-14 | github.com | record → | |
| Respondus | high | 2025-07-24 | github.com | record → |
| Microsoft | high | 2025-06-25 | undercodetesting.com | record → |
| CrowdStrike | high | 2025-03-05 | finalfrontiersecurity.com | record → |
| Skyhigh Security | high | 2024-10-29 | github.com | record → |
| Trellix | medium | 2024-10-29 | github.com | record → |
| Pearson | high | 2024-06-18 | github.com | record → |
| SentinelOne | high | 2023-12-08 | securityaffairs.com | record → |
| Palo Alto | high | 2023-12-08 | securityaffairs.com | record → |
| CrowdStrike | high | 2023-12-08 | securityaffairs.com | record → |
| Microsoft | high | 2023-12-08 | securityaffairs.com | record → |
| Cybereason | high | 2023-12-08 | securityaffairs.com | record → |
| Microsoft | high | 2023-11-16 | chayanin-mews.medium.com | record → |
| Microsoft | medium | 2023-10-28 | github.com | record → |
| Microsoft | medium | 2023-08-21 | github.com | record → |
| STRANGETRINITY | high | 2023-08-03 | riccardoancarani.github.io | record → |
Counts reflect distinct publicly-reported events on record; absence of an entry means no confirmed public report is on file.