.. /Ttdinject.exe
Star

Used by Windows 1809 and newer to Debug Time Travel (Underlying call of tttracer.exe)


Paths:

Resources:
Acknowledgements:

Detection:

Execute

Execute calc using ttdinject.exe. Requires administrator privileges. A log file will be created in tmp.run. The log file can be changed, but the length (7) has to be updated.
TTDInject.exe /ClientParams "7 tmp.run 0 0 0 0 0 0 0 0 0 0" /Launch "C:/Windows/System32/calc.exe"
Usecase: Spawn process using other binary
Privileges required: Administrator
OS: Windows 10 2004 and above, Windows 11
MITRE ATT&CK®: T1127



Execute calc using ttdinject.exe. Requires administrator privileges. A log file will be created in tmp.run. The log file can be changed, but the length (7) has to be updated.
ttdinject.exe /ClientScenario TTDRecorder /ddload 0 /ClientParams "7 tmp.run 0 0 0 0 0 0 0 0 0 0" /launch "C:/Windows/System32/calc.exe"
Usecase: Spawn process using other binary
Privileges required: Administrator
OS: Windows 10 1909 and below
MITRE ATT&CK®: T1127