Cybersecurityadvanced1 min read

Process Hollowing

N/A

进程挖空

Process Hollowing · N/A · 进程挖空 · PRAH-ses HOL-oh-ing · hollow process · runPE style · Cybersecurity · malware · windows · evasionCybersecurityhollow process runPE style

/PRAH-ses HOL-oh-ing/

Also known as: hollow process, runPE style

Last updated August 9, 2026

Definition

Process hollowing starts a legitimate process in a suspended state, replaces its memory with malware, then resumes it.

Real-World Example

A hollowed svchost.exe that actually runs a backdoor while keeping the original process name.

References

discuss://translation · public

Translation discussion

Anyone can read and write here. Pick a display name — no email or account. Please keep the thread constructive. Thumb up a rendering you agree with — that helps the editor see consensus; it does not publish the term by itself. You can edit or delete your own comments from this browser; another device or cleared site data cannot.

Community lists who wrote, on which term, and when.

Loading discussion…