{"id":1915,"date":"2026-07-20T23:30:50","date_gmt":"2026-07-20T22:30:50","guid":{"rendered":"https:\/\/www.halkynconsulting.co.uk\/a\/?p=1915"},"modified":"2026-07-20T23:42:34","modified_gmt":"2026-07-20T22:42:34","slug":"reflected-code-injection","status":"publish","type":"post","link":"https:\/\/www.halkynconsulting.co.uk\/a\/2026\/07\/reflected-code-injection\/","title":{"rendered":"Reflective Code Injection Attacks &#8211; An Overview for Incident Responders"},"content":{"rendered":"<p><em>Note: This article was originally posted to LinkedIn on 2023-11-16.<\/em><\/p>\n<h2>Introduction to Reflective Code Injection<\/h2>\n<p>Reflective code injection is a sophisticated technique used by attackers to execute arbitrary code within the memory space of a process without requiring external modules or files. This type of attack is particularly stealthy as it leaves minimal traces on the file system, making detection challenging.<\/p>\n<h3>Reflective Code Injection in Windows<\/h3>\n<p><strong>Overview<\/strong>: In Windows, reflective code injection involves injecting code into a legitimate process&#8217;s memory space. This is often achieved through APIs like VirtualAllocEx and WriteProcessMemory, followed by execution control transfer using mechanisms such as CreateRemoteThread.<\/p>\n<p><strong>Execution Flow<\/strong>: The injected code, typically a DLL, is loaded directly from memory, bypassing the standard Windows loader. This is achieved by manually performing tasks usually handled by the loader, such as handling relocations, resolving imports, and executing TLS callbacks.<\/p>\n<p><strong>Stealth and Evasion<\/strong>: This technique is favoured for evading detection tools that monitor file-based module loading activities, as the injected code does not appear in the standard list of loaded modules of the process.<\/p>\n<h3>Reflective Code Injection in Linux<\/h3>\n<p><strong>Overview<\/strong>: In Linux, reflective code injection can be executed using techniques like process memory manipulation via ptrace or manipulating memory directly through \/proc\/[pid]\/mem.<\/p>\n<p><strong>Execution Flow<\/strong>: The injected code often involves shellcode or ELF-formatted payloads. Unlike Windows, Linux does not have a unified loader mechanism; thus, the injected code must be more self-contained, handling its own dependencies.<\/p>\n<p><strong>Comparison with Windows<\/strong>: Unlike Windows, Linux&#8217;s diverse range of process manipulation capabilities offers a broader attack surface for reflective code injection, but the lack of a standardised injection mechanism makes the attacks more complex and varied.<\/p>\n<h2>Detection Techniques:<\/h2>\n<h3>Memory Analysis<\/h3>\n<p><strong>Memory Analysis in Windows<\/strong>: In Windows, tools like Process Hacker or the Windows Debugger (WinDbg) can be used to inspect the Virtual Address Descriptor (VAD) tree of a process. Unusual or unlinked memory regions, especially those with execute permissions, may indicate injected code. You can also use the incredibly effective\u00a0<a href=\"https:\/\/github.com\/ufrisk\/MemProcFS\" target=\"_blank\" rel=\"noopener\">MemProcFS<\/a>. This is probably one of the most exciting developments in memory analysis in the last 5 years.<\/p>\n<p><strong>Memory Analysis in Linux<\/strong>: In Linux, the \/proc filesystem is a key resource. By examining \/proc\/[pid]\/maps and \/proc\/[pid]\/mem, one can identify anomalies in memory mappings and contents.<\/p>\n<h3>Detecting Reflective Code Injection<\/h3>\n<p><strong>Anomalies in Memory Regions<\/strong>: Unusual memory regions, such as those with RWX (read, write, execute) permissions, should be treated with suspicion. In both Windows and Linux, these regions could indicate the presence of injected code.<\/p>\n<p><strong>Discrepancies in Process Behaviour<\/strong>: Monitoring for discrepancies in process behaviour, such as a text editor executing network operations, can be a sign of code injection.<\/p>\n<p><strong>Use of Uncommon System Calls<\/strong>: In Linux, an increase in the use of system calls related to memory manipulation (like mmap, mprotect, or ptrace) can be a red flag. Similarly, in Windows, frequent calls to memory manipulation APIs outside of normal operation context may indicate injection.<\/p>\n<h3>Incident Response and Threat Hunting<\/h3>\n<p><strong>Hunting for Reflective Code Injection<\/strong>: Incident responders and threat hunters should monitor for signs of anomalous memory and process behaviour. Tools like Volatility for memory forensics, or YARA rules to identify known patterns of injection, can be effective. In Linux, analysing the \/proc filesystem for each process can reveal inconsistencies indicative of injection.<\/p>\n<h3>Summary<\/h3>\n<p>Reflective code injection remains a potent threat in both Windows and Linux environments. Understanding the mechanisms of these attacks and employing thorough memory analysis techniques are crucial for effective detection and response. As attackers evolve their methods, continuous education and adaptation of detection strategies remain essential for cybersecurity professionals.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Reflective code injection lets attackers execute code directly in process memory, leaving minimal file-system traces. This overview explains the technique on Windows and Linux, then covers detection methods for incident responders: VAD tree inspection, \/proc analysis, RWX memory anomalies, suspicious system calls, and tools such as MemProcFS, Volatility and YARA.<\/p>\n","protected":false},"author":4,"featured_media":1916,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"ocean_post_layout":"","ocean_both_sidebars_style":"","ocean_both_sidebars_content_width":0,"ocean_both_sidebars_sidebars_width":0,"ocean_sidebar":"","ocean_second_sidebar":"","ocean_disable_margins":"enable","ocean_add_body_class":"","ocean_shortcode_before_top_bar":"","ocean_shortcode_after_top_bar":"","ocean_shortcode_before_header":"","ocean_shortcode_after_header":"","ocean_has_shortcode":"","ocean_shortcode_after_title":"","ocean_shortcode_before_footer_widgets":"","ocean_shortcode_after_footer_widgets":"","ocean_shortcode_before_footer_bottom":"","ocean_shortcode_after_footer_bottom":"","ocean_display_top_bar":"default","ocean_display_header":"default","ocean_header_style":"","ocean_center_header_left_menu":"","ocean_custom_header_template":"","ocean_custom_logo":0,"ocean_custom_retina_logo":0,"ocean_custom_logo_max_width":0,"ocean_custom_logo_tablet_max_width":0,"ocean_custom_logo_mobile_max_width":0,"ocean_custom_logo_max_height":0,"ocean_custom_logo_tablet_max_height":0,"ocean_custom_logo_mobile_max_height":0,"ocean_header_custom_menu":"","ocean_menu_typo_font_family":"","ocean_menu_typo_font_subset":"","ocean_menu_typo_font_size":0,"ocean_menu_typo_font_size_tablet":0,"ocean_menu_typo_font_size_mobile":0,"ocean_menu_typo_font_size_unit":"px","ocean_menu_typo_font_weight":"","ocean_menu_typo_font_weight_tablet":"","ocean_menu_typo_font_weight_mobile":"","ocean_menu_typo_transform":"","ocean_menu_typo_transform_tablet":"","ocean_menu_typo_transform_mobile":"","ocean_menu_typo_line_height":0,"ocean_menu_typo_line_height_tablet":0,"ocean_menu_typo_line_height_mobile":0,"ocean_menu_typo_line_height_unit":"","ocean_menu_typo_spacing":0,"ocean_menu_typo_spacing_tablet":0,"ocean_menu_typo_spacing_mobile":0,"ocean_menu_typo_spacing_unit":"","ocean_menu_link_color":"","ocean_menu_link_color_hover":"","ocean_menu_link_color_active":"","ocean_menu_link_background":"","ocean_menu_link_hover_background":"","ocean_menu_link_active_background":"","ocean_menu_social_links_bg":"","ocean_menu_social_hover_links_bg":"","ocean_menu_social_links_color":"","ocean_menu_social_hover_links_color":"","ocean_disable_title":"default","ocean_disable_heading":"default","ocean_post_title":"","ocean_post_subheading":"","ocean_post_title_style":"","ocean_post_title_background_color":"","ocean_post_title_background":0,"ocean_post_title_bg_image_position":"","ocean_post_title_bg_image_attachment":"","ocean_post_title_bg_image_repeat":"","ocean_post_title_bg_image_size":"","ocean_post_title_height":0,"ocean_post_title_bg_overlay":0.5,"ocean_post_title_bg_overlay_color":"","ocean_disable_breadcrumbs":"default","ocean_breadcrumbs_color":"","ocean_breadcrumbs_separator_color":"","ocean_breadcrumbs_links_color":"","ocean_breadcrumbs_links_hover_color":"","ocean_display_footer_widgets":"default","ocean_display_footer_bottom":"default","ocean_custom_footer_template":"","_jetpack_newsletter_access":"","_jetpack_dont_email_post_to_subs":false,"_jetpack_newsletter_tier_id":0,"_jetpack_memberships_contains_paywalled_content":false,"_jetpack_feature_clip_id":0,"_jetpack_memberships_contains_paid_content":false,"ocean_post_oembed":"","ocean_post_self_hosted_media":"","ocean_post_video_embed":"","ocean_link_format":"","ocean_link_format_target":"self","ocean_quote_format":"","ocean_quote_format_link":"post","ocean_gallery_link_images":"on","ocean_gallery_id":[],"footnotes":"","jetpack_publicize_message":"","jetpack_publicize_feature_enabled":true,"jetpack_social_post_already_shared":true,"jetpack_social_options":{"image_generator_settings":{"template":"highway","default_image_id":0,"font":"","enabled":false},"version":2},"jetpack_post_was_ever_published":false},"categories":[5],"tags":[159,147,137],"class_list":["post-1915","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-security","tag-cyber-security","tag-cybersecurity","tag-incident-response","entry","has-media"],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v28.1 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>Reflective Code Injection Attacks - An Overview for Incident Responders - Halkyn Security Blog<\/title>\n<meta name=\"description\" content=\"How reflective code injection works on Windows &amp; Linux, plus detection techniques for incident responders using memory analysis and behavioural signs.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/www.halkynconsulting.co.uk\/a\/2026\/07\/reflected-code-injection\/\" \/>\n<meta property=\"og:locale\" content=\"en_GB\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Reflective Code Injection Attacks - An Overview for Incident Responders - Halkyn Security Blog\" \/>\n<meta property=\"og:description\" content=\"How reflective code injection works on Windows &amp; Linux, plus detection techniques for incident responders using memory analysis and behavioural signs.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/www.halkynconsulting.co.uk\/a\/2026\/07\/reflected-code-injection\/\" \/>\n<meta property=\"og:site_name\" content=\"Halkyn Security Blog\" \/>\n<meta property=\"article:published_time\" content=\"2026-07-20T22:30:50+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2026-07-20T22:42:34+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/www.halkynconsulting.co.uk\/a\/wp-content\/uploads\/2026\/07\/Gemini_Generated_Image_zgux17zgux17zgux-1024x572.png\" \/>\n\t<meta property=\"og:image:width\" content=\"1024\" \/>\n\t<meta property=\"og:image:height\" content=\"572\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/png\" \/>\n<meta name=\"author\" content=\"Staff Writer\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:creator\" content=\"@HalkynSecurity\" \/>\n<meta name=\"twitter:site\" content=\"@HalkynSecurity\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"Staff Writer\" \/>\n\t<meta name=\"twitter:label2\" content=\"Estimated reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"3 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\\\/\\\/www.halkynconsulting.co.uk\\\/a\\\/2026\\\/07\\\/reflected-code-injection\\\/#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.halkynconsulting.co.uk\\\/a\\\/2026\\\/07\\\/reflected-code-injection\\\/\"},\"author\":{\"name\":\"Staff Writer\",\"@id\":\"https:\\\/\\\/www.halkynconsulting.co.uk\\\/a\\\/#\\\/schema\\\/person\\\/58ede4740a169265ec326ea4afd1c97d\"},\"headline\":\"Reflective Code Injection Attacks &#8211; An Overview for Incident Responders\",\"datePublished\":\"2026-07-20T22:30:50+00:00\",\"dateModified\":\"2026-07-20T22:42:34+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/www.halkynconsulting.co.uk\\\/a\\\/2026\\\/07\\\/reflected-code-injection\\\/\"},\"wordCount\":607,\"commentCount\":0,\"publisher\":{\"@id\":\"https:\\\/\\\/www.halkynconsulting.co.uk\\\/a\\\/#organization\"},\"image\":{\"@id\":\"https:\\\/\\\/www.halkynconsulting.co.uk\\\/a\\\/2026\\\/07\\\/reflected-code-injection\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/i0.wp.com\\\/www.halkynconsulting.co.uk\\\/a\\\/wp-content\\\/uploads\\\/2026\\\/07\\\/Gemini_Generated_Image_zgux17zgux17zgux-scaled.png?fit=2560%2C1429&ssl=1\",\"keywords\":[\"Cyber Security\",\"Cybersecurity\",\"Incident Response\"],\"articleSection\":[\"Security\"],\"inLanguage\":\"en-GB\",\"potentialAction\":[{\"@type\":\"CommentAction\",\"name\":\"Comment\",\"target\":[\"https:\\\/\\\/www.halkynconsulting.co.uk\\\/a\\\/2026\\\/07\\\/reflected-code-injection\\\/#respond\"]}]},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/www.halkynconsulting.co.uk\\\/a\\\/2026\\\/07\\\/reflected-code-injection\\\/\",\"url\":\"https:\\\/\\\/www.halkynconsulting.co.uk\\\/a\\\/2026\\\/07\\\/reflected-code-injection\\\/\",\"name\":\"Reflective Code Injection Attacks - An Overview for Incident Responders - Halkyn Security Blog\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.halkynconsulting.co.uk\\\/a\\\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/www.halkynconsulting.co.uk\\\/a\\\/2026\\\/07\\\/reflected-code-injection\\\/#primaryimage\"},\"image\":{\"@id\":\"https:\\\/\\\/www.halkynconsulting.co.uk\\\/a\\\/2026\\\/07\\\/reflected-code-injection\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/i0.wp.com\\\/www.halkynconsulting.co.uk\\\/a\\\/wp-content\\\/uploads\\\/2026\\\/07\\\/Gemini_Generated_Image_zgux17zgux17zgux-scaled.png?fit=2560%2C1429&ssl=1\",\"datePublished\":\"2026-07-20T22:30:50+00:00\",\"dateModified\":\"2026-07-20T22:42:34+00:00\",\"description\":\"How reflective code injection works on Windows & Linux, plus detection techniques for incident responders using memory analysis and behavioural signs.\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/www.halkynconsulting.co.uk\\\/a\\\/2026\\\/07\\\/reflected-code-injection\\\/#breadcrumb\"},\"inLanguage\":\"en-GB\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/www.halkynconsulting.co.uk\\\/a\\\/2026\\\/07\\\/reflected-code-injection\\\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-GB\",\"@id\":\"https:\\\/\\\/www.halkynconsulting.co.uk\\\/a\\\/2026\\\/07\\\/reflected-code-injection\\\/#primaryimage\",\"url\":\"https:\\\/\\\/i0.wp.com\\\/www.halkynconsulting.co.uk\\\/a\\\/wp-content\\\/uploads\\\/2026\\\/07\\\/Gemini_Generated_Image_zgux17zgux17zgux-scaled.png?fit=2560%2C1429&ssl=1\",\"contentUrl\":\"https:\\\/\\\/i0.wp.com\\\/www.halkynconsulting.co.uk\\\/a\\\/wp-content\\\/uploads\\\/2026\\\/07\\\/Gemini_Generated_Image_zgux17zgux17zgux-scaled.png?fit=2560%2C1429&ssl=1\",\"width\":2560,\"height\":1429},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/www.halkynconsulting.co.uk\\\/a\\\/2026\\\/07\\\/reflected-code-injection\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Halkyn Security\",\"item\":\"https:\\\/\\\/www.halkynconsulting.co.uk\\\/a\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Security\",\"item\":\"https:\\\/\\\/www.halkynconsulting.co.uk\\\/a\\\/category\\\/security\\\/\"},{\"@type\":\"ListItem\",\"position\":3,\"name\":\"Reflective Code Injection Attacks &#8211; An Overview for Incident Responders\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/www.halkynconsulting.co.uk\\\/a\\\/#website\",\"url\":\"https:\\\/\\\/www.halkynconsulting.co.uk\\\/a\\\/\",\"name\":\"Halkyn Security Blog\",\"description\":\"Specialist Security &amp; Risk Management Consultants\",\"publisher\":{\"@id\":\"https:\\\/\\\/www.halkynconsulting.co.uk\\\/a\\\/#organization\"},\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/www.halkynconsulting.co.uk\\\/a\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-GB\"},{\"@type\":\"Organization\",\"@id\":\"https:\\\/\\\/www.halkynconsulting.co.uk\\\/a\\\/#organization\",\"name\":\"Halkyn Consulting\",\"url\":\"https:\\\/\\\/www.halkynconsulting.co.uk\\\/a\\\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-GB\",\"@id\":\"https:\\\/\\\/www.halkynconsulting.co.uk\\\/a\\\/#\\\/schema\\\/logo\\\/image\\\/\",\"url\":\"https:\\\/\\\/i0.wp.com\\\/www.halkynconsulting.co.uk\\\/a\\\/wp-content\\\/uploads\\\/2011\\\/07\\\/Untitled-1.png?fit=990%2C170&ssl=1\",\"contentUrl\":\"https:\\\/\\\/i0.wp.com\\\/www.halkynconsulting.co.uk\\\/a\\\/wp-content\\\/uploads\\\/2011\\\/07\\\/Untitled-1.png?fit=990%2C170&ssl=1\",\"width\":\"990\",\"height\":\"170\",\"caption\":\"Halkyn Consulting\"},\"image\":{\"@id\":\"https:\\\/\\\/www.halkynconsulting.co.uk\\\/a\\\/#\\\/schema\\\/logo\\\/image\\\/\"},\"sameAs\":[\"https:\\\/\\\/x.com\\\/HalkynSecurity\",\"https:\\\/\\\/www.linkedin.com\\\/company\\\/2329571\"]},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/www.halkynconsulting.co.uk\\\/a\\\/#\\\/schema\\\/person\\\/58ede4740a169265ec326ea4afd1c97d\",\"name\":\"Staff Writer\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-GB\",\"@id\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/730d6d5d0dc5b9af3fc83ce16468007ab0cb3ea422ff32561707ef3914d36d93?s=96&d=retro&r=g\",\"url\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/730d6d5d0dc5b9af3fc83ce16468007ab0cb3ea422ff32561707ef3914d36d93?s=96&d=retro&r=g\",\"contentUrl\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/730d6d5d0dc5b9af3fc83ce16468007ab0cb3ea422ff32561707ef3914d36d93?s=96&d=retro&r=g\",\"caption\":\"Staff Writer\"},\"url\":\"https:\\\/\\\/www.halkynconsulting.co.uk\\\/a\\\/author\\\/content-team\\\/\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"Reflective Code Injection Attacks - An Overview for Incident Responders - Halkyn Security Blog","description":"How reflective code injection works on Windows & Linux, plus detection techniques for incident responders using memory analysis and behavioural signs.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/www.halkynconsulting.co.uk\/a\/2026\/07\/reflected-code-injection\/","og_locale":"en_GB","og_type":"article","og_title":"Reflective Code Injection Attacks - An Overview for Incident Responders - Halkyn Security Blog","og_description":"How reflective code injection works on Windows & Linux, plus detection techniques for incident responders using memory analysis and behavioural signs.","og_url":"https:\/\/www.halkynconsulting.co.uk\/a\/2026\/07\/reflected-code-injection\/","og_site_name":"Halkyn Security Blog","article_published_time":"2026-07-20T22:30:50+00:00","article_modified_time":"2026-07-20T22:42:34+00:00","og_image":[{"width":1024,"height":572,"url":"https:\/\/www.halkynconsulting.co.uk\/a\/wp-content\/uploads\/2026\/07\/Gemini_Generated_Image_zgux17zgux17zgux-1024x572.png","type":"image\/png"}],"author":"Staff Writer","twitter_card":"summary_large_image","twitter_creator":"@HalkynSecurity","twitter_site":"@HalkynSecurity","twitter_misc":{"Written by":"Staff Writer","Estimated reading time":"3 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/www.halkynconsulting.co.uk\/a\/2026\/07\/reflected-code-injection\/#article","isPartOf":{"@id":"https:\/\/www.halkynconsulting.co.uk\/a\/2026\/07\/reflected-code-injection\/"},"author":{"name":"Staff Writer","@id":"https:\/\/www.halkynconsulting.co.uk\/a\/#\/schema\/person\/58ede4740a169265ec326ea4afd1c97d"},"headline":"Reflective Code Injection Attacks &#8211; An Overview for Incident Responders","datePublished":"2026-07-20T22:30:50+00:00","dateModified":"2026-07-20T22:42:34+00:00","mainEntityOfPage":{"@id":"https:\/\/www.halkynconsulting.co.uk\/a\/2026\/07\/reflected-code-injection\/"},"wordCount":607,"commentCount":0,"publisher":{"@id":"https:\/\/www.halkynconsulting.co.uk\/a\/#organization"},"image":{"@id":"https:\/\/www.halkynconsulting.co.uk\/a\/2026\/07\/reflected-code-injection\/#primaryimage"},"thumbnailUrl":"https:\/\/i0.wp.com\/www.halkynconsulting.co.uk\/a\/wp-content\/uploads\/2026\/07\/Gemini_Generated_Image_zgux17zgux17zgux-scaled.png?fit=2560%2C1429&ssl=1","keywords":["Cyber Security","Cybersecurity","Incident Response"],"articleSection":["Security"],"inLanguage":"en-GB","potentialAction":[{"@type":"CommentAction","name":"Comment","target":["https:\/\/www.halkynconsulting.co.uk\/a\/2026\/07\/reflected-code-injection\/#respond"]}]},{"@type":"WebPage","@id":"https:\/\/www.halkynconsulting.co.uk\/a\/2026\/07\/reflected-code-injection\/","url":"https:\/\/www.halkynconsulting.co.uk\/a\/2026\/07\/reflected-code-injection\/","name":"Reflective Code Injection Attacks - An Overview for Incident Responders - Halkyn Security Blog","isPartOf":{"@id":"https:\/\/www.halkynconsulting.co.uk\/a\/#website"},"primaryImageOfPage":{"@id":"https:\/\/www.halkynconsulting.co.uk\/a\/2026\/07\/reflected-code-injection\/#primaryimage"},"image":{"@id":"https:\/\/www.halkynconsulting.co.uk\/a\/2026\/07\/reflected-code-injection\/#primaryimage"},"thumbnailUrl":"https:\/\/i0.wp.com\/www.halkynconsulting.co.uk\/a\/wp-content\/uploads\/2026\/07\/Gemini_Generated_Image_zgux17zgux17zgux-scaled.png?fit=2560%2C1429&ssl=1","datePublished":"2026-07-20T22:30:50+00:00","dateModified":"2026-07-20T22:42:34+00:00","description":"How reflective code injection works on Windows & Linux, plus detection techniques for incident responders using memory analysis and behavioural signs.","breadcrumb":{"@id":"https:\/\/www.halkynconsulting.co.uk\/a\/2026\/07\/reflected-code-injection\/#breadcrumb"},"inLanguage":"en-GB","potentialAction":[{"@type":"ReadAction","target":["https:\/\/www.halkynconsulting.co.uk\/a\/2026\/07\/reflected-code-injection\/"]}]},{"@type":"ImageObject","inLanguage":"en-GB","@id":"https:\/\/www.halkynconsulting.co.uk\/a\/2026\/07\/reflected-code-injection\/#primaryimage","url":"https:\/\/i0.wp.com\/www.halkynconsulting.co.uk\/a\/wp-content\/uploads\/2026\/07\/Gemini_Generated_Image_zgux17zgux17zgux-scaled.png?fit=2560%2C1429&ssl=1","contentUrl":"https:\/\/i0.wp.com\/www.halkynconsulting.co.uk\/a\/wp-content\/uploads\/2026\/07\/Gemini_Generated_Image_zgux17zgux17zgux-scaled.png?fit=2560%2C1429&ssl=1","width":2560,"height":1429},{"@type":"BreadcrumbList","@id":"https:\/\/www.halkynconsulting.co.uk\/a\/2026\/07\/reflected-code-injection\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Halkyn Security","item":"https:\/\/www.halkynconsulting.co.uk\/a\/"},{"@type":"ListItem","position":2,"name":"Security","item":"https:\/\/www.halkynconsulting.co.uk\/a\/category\/security\/"},{"@type":"ListItem","position":3,"name":"Reflective Code Injection Attacks &#8211; An Overview for Incident Responders"}]},{"@type":"WebSite","@id":"https:\/\/www.halkynconsulting.co.uk\/a\/#website","url":"https:\/\/www.halkynconsulting.co.uk\/a\/","name":"Halkyn Security Blog","description":"Specialist Security &amp; Risk Management Consultants","publisher":{"@id":"https:\/\/www.halkynconsulting.co.uk\/a\/#organization"},"potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/www.halkynconsulting.co.uk\/a\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-GB"},{"@type":"Organization","@id":"https:\/\/www.halkynconsulting.co.uk\/a\/#organization","name":"Halkyn Consulting","url":"https:\/\/www.halkynconsulting.co.uk\/a\/","logo":{"@type":"ImageObject","inLanguage":"en-GB","@id":"https:\/\/www.halkynconsulting.co.uk\/a\/#\/schema\/logo\/image\/","url":"https:\/\/i0.wp.com\/www.halkynconsulting.co.uk\/a\/wp-content\/uploads\/2011\/07\/Untitled-1.png?fit=990%2C170&ssl=1","contentUrl":"https:\/\/i0.wp.com\/www.halkynconsulting.co.uk\/a\/wp-content\/uploads\/2011\/07\/Untitled-1.png?fit=990%2C170&ssl=1","width":"990","height":"170","caption":"Halkyn Consulting"},"image":{"@id":"https:\/\/www.halkynconsulting.co.uk\/a\/#\/schema\/logo\/image\/"},"sameAs":["https:\/\/x.com\/HalkynSecurity","https:\/\/www.linkedin.com\/company\/2329571"]},{"@type":"Person","@id":"https:\/\/www.halkynconsulting.co.uk\/a\/#\/schema\/person\/58ede4740a169265ec326ea4afd1c97d","name":"Staff Writer","image":{"@type":"ImageObject","inLanguage":"en-GB","@id":"https:\/\/secure.gravatar.com\/avatar\/730d6d5d0dc5b9af3fc83ce16468007ab0cb3ea422ff32561707ef3914d36d93?s=96&d=retro&r=g","url":"https:\/\/secure.gravatar.com\/avatar\/730d6d5d0dc5b9af3fc83ce16468007ab0cb3ea422ff32561707ef3914d36d93?s=96&d=retro&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/730d6d5d0dc5b9af3fc83ce16468007ab0cb3ea422ff32561707ef3914d36d93?s=96&d=retro&r=g","caption":"Staff Writer"},"url":"https:\/\/www.halkynconsulting.co.uk\/a\/author\/content-team\/"}]}},"jetpack_publicize_connections":[],"jetpack_featured_media_url":"https:\/\/i0.wp.com\/www.halkynconsulting.co.uk\/a\/wp-content\/uploads\/2026\/07\/Gemini_Generated_Image_zgux17zgux17zgux-scaled.png?fit=2560%2C1429&ssl=1","jetpack_sharing_enabled":true,"jetpack_shortlink":"https:\/\/wp.me\/p9yHvD-uT","jetpack_likes_enabled":true,"_links":{"self":[{"href":"https:\/\/www.halkynconsulting.co.uk\/a\/wp-json\/wp\/v2\/posts\/1915","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.halkynconsulting.co.uk\/a\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.halkynconsulting.co.uk\/a\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.halkynconsulting.co.uk\/a\/wp-json\/wp\/v2\/users\/4"}],"replies":[{"embeddable":true,"href":"https:\/\/www.halkynconsulting.co.uk\/a\/wp-json\/wp\/v2\/comments?post=1915"}],"version-history":[{"count":1,"href":"https:\/\/www.halkynconsulting.co.uk\/a\/wp-json\/wp\/v2\/posts\/1915\/revisions"}],"predecessor-version":[{"id":1917,"href":"https:\/\/www.halkynconsulting.co.uk\/a\/wp-json\/wp\/v2\/posts\/1915\/revisions\/1917"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.halkynconsulting.co.uk\/a\/wp-json\/wp\/v2\/media\/1916"}],"wp:attachment":[{"href":"https:\/\/www.halkynconsulting.co.uk\/a\/wp-json\/wp\/v2\/media?parent=1915"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.halkynconsulting.co.uk\/a\/wp-json\/wp\/v2\/categories?post=1915"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.halkynconsulting.co.uk\/a\/wp-json\/wp\/v2\/tags?post=1915"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}