Used by Windows 1809 and newer to Debug Time Travel (Underlying call of tttracer.exe)
Paths:
Acknowledgement:
Oddvar Moe - @oddvarmoe
Maxime Nadeau - @m_nad0
Detection:
Parent child relationship. Ttdinject.exe parent for executed command
Multiple queries made to the IFEO registry key of an untrusted executable (Ex. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\payload.exe") from the ttdinject.exe process
TTDInject.exe /ClientParams "7 tmp.run 0 0 0 0 0 0 0 0 0 0" /Launch "C:/Windows/System32/calc.exe"
Usecase:Spawn process using other binary
ttdinject.exe /ClientScenario TTDRecorder /ddload 0 /ClientParams "7 tmp.run 0 0 0 0 0 0 0 0 0 0" /launch "C:/Windows/System32/calc.exe"
Usecase:Spawn process using other binary