# Thread Pool Timer Process Injection > ⚠ **Educational Research Only** > This repository contains security research for **educational purposes** and **authorized use only**. > Use responsibly and in accordance with all applicable laws and regulations. --- ## Overview **Thread Pool Timer Process Injection** is a novel technique that leverages the Windows thread pool infrastructure to execute shellcode. By combining traditional DLL injection with the `CreateThreadpoolTimer` API, this method enables in-memory code execution through legitimate system-managed threads—potentially bypassing many modern detection mechanisms. This approach introduces a stealthy execution vector that avoids classic API hooks such as `CreateRemoteThread`, `NtCreateThreadEx`, and APCs, making it highly attractive for red team operations and malware research. --- ![Recording 2025-07-16 1317152323](https://github.com/user-attachments/assets/fe7d0f6f-a1e0-4198-8e06-dec994e42bd6) --- --- 🛠️ Technical Implementation image --- ## 🧩 Core Components ### 🛠 Main Injector (`Injector.cpp`) - Process enumeration and targeting logic - DLL injection using `CreateRemoteThread` and `LoadLibraryW` - Error handling and execution status reporting ### ⏲ Timer DLL (`TimerDLL.cpp`) - Timer-based shellcode execution implementation - `TP_CALLBACK_ENVIRON` structure setup for thread pool configuration - Execution of shellcode via the timer callback ## 📋 API Sequence ### 🧪 Traditional Injection APIs ```cpp OpenProcess() // Access the target process VirtualAllocEx() // Allocate memory in remote process WriteProcessMemory() // Write shellcode or DLL path CreateRemoteThread() // Create a remote thread to execute payload LoadLibraryW() // Load a DLL via thread execution ⏱️ Thread Pool Timer-Based APIs InitializeThreadpoolEnvironment() // Configure threadpool callback environment CreateThreadpoolTimer() // Create a timer object SetThreadpoolTimer() // Schedule the timer for execution TimerCallback() // Callback function that executes shellcode