Pool Party is SafeBreach’s name for eight process-injection variants that use Windows user-mode thread-pool mechanisms. SafeBreach reported in 2023 that none of the five EDR products it tested detected or prevented those variants under its test conditions. That result describes a specific, dated test—not the current capability of every EDR. Later vendor statements described detection updates and coverage, but they were not fresh independent tests.
What is Pool Party process injection?
Process injection is a broad class of techniques in which activity is directed into another process. SafeBreach’s Pool Party research explored ways to use Windows user-mode thread-pool mechanisms to arrange execution inside a target process. The researchers named eight variants, combining thread-pool concepts in different ways.
Windows processes can use a user-mode thread pool by default. Worker threads consume work managed through a worker factory and associated queues. SafeBreach focused on four relevant areas: worker factories, task queues, I/O-completion queues, and timer queues. The significance for defenders is that execution can involve familiar Windows mechanisms and a process that otherwise appears legitimate; process identity alone may not explain whether its behavior is expected.
SafeBreach described injection in terms of memory allocation, writing, and execution primitives. Tomer Bar, SafeBreach’s VP of Security Research, told Help Net Security that the products he observed allowed the first two steps and focused detection on remote execution. That is the researcher’s explanation of observed detection emphasis, not a verified description of how every EDR works.
What’s actually slowing this PC down?
Pick the symptom - the matching free tool is one click away.
#1 Best Overall
What did SafeBreach’s 2023 EDR test find?
SafeBreach Labs said it tested all eight variants against five products it could access: Palo Alto Cortex, SentinelOne EDR, CrowdStrike Falcon, Microsoft Defender for Endpoint, and Cybereason EDR. It reported that none detected or prevented the variants in that test, characterizing the outcome as a 100 percent success rate for the techniques. The figure applies only to those eight variants and five products under SafeBreach’s test conditions; the researchers said they could not test every product on the market.
This finding is useful evidence that thread-pool behavior posed a detection challenge at disclosure time. It is not a current benchmark, an industry-wide failure rate, or proof that all versions and configurations of the named products remain vulnerable to the same behavior.
Rank #2
What did vendors say after disclosure?
In a December 12, 2023 follow-up, Help Net Security reported product-specific vendor responses. Their statements are distinct from the SafeBreach test and should not be read as independent validation.
| Product or vendor | Disclosure-era statement | Evidence and limits |
|---|---|---|
| CrowdStrike Falcon | CrowdStrike said a Falcon sensor update added visibility and detection for the specific technique. | Vendor statement reported by Help Net Security on December 12, 2023; the report does not establish current coverage across sensor versions or configurations. |
| SentinelOne | SentinelOne said its products detected the technique and could terminate it depending on policy. | Vendor statement reported by Help Net Security on December 12, 2023; detection and termination depend on the applicable policy. |
| Microsoft Defender for Endpoint | Microsoft had nothing to add at that time, according to the report. | This is not evidence for or against current detection coverage. |
| FortiEDR | FortiGuard said FortiEDR blocked all variants out of the box using a kernel-behavior policy, naming Collector versions 5.2.0 and 5.2.2. | Fortinet’s vendor claim in a December 20, 2023 report, not an independent evaluation. |
These reports do not support a present-day ranking of EDR products. They differ in source, date, product version, and whether the statement concerns visibility, detection, prevention, or policy-dependent termination. None establishes current coverage for every product family, configuration, or sensor version.
Rank #3
Can EDR detect Pool Party today?
It can be detected or blocked according to later vendor statements, but the available evidence does not establish present-day coverage across the market. SafeBreach’s finding records its 2023 test; CrowdStrike, SentinelOne, and Fortinet reported responses in December 2023. Those claims do not substitute for current, independent testing in an organization’s own environment.
The cited sources also do not establish how often Pool Party is used in real attacks. FortiGuard wrote in December 2023 that it had not identified threat actors using the technique at that time. That dated observation should not be treated as a current prevalence estimate.
Rank #4
- Used Book in Good Condition
What should defenders do?
Investigate behavior in context rather than treating a trusted process name as proof that its activity is benign. SafeBreach researcher Alon Leviev wrote that organizations should “enhance their focus on detecting anomalies, rather than placing complete trust in processes based solely on their identity.”
- Review endpoint alerts and telemetry for unusual activity within processes that ordinarily appear trusted, including unexpected use of thread-pool mechanisms.
- Ask vendors specifically whether their current sensor versions and configurations detect or prevent behavior associated with all eight reported variants. Distinguish a detection alert from prevention or termination.
- Validate endpoint controls against the relevant behaviors in an authorized test environment, using a controlled security assessment or breach-and-attack simulation. Record the product version, policy, test scope, and observed response so results are reproducible.
- When a vendor reports coverage, request details on supported versions, required policies, and the response action. A broad statement that a product “covers” a technique may mean visibility, alerting, blocking, or termination.
SafeBreach says its platform includes original attack content for customers to validate controls against these flows. That describes the vendor’s offering; organizations can also assess controls through other appropriately authorized testing methods.
Do these 3 things before closing this tab:
1Fix the driver behind crashes, sound loss and screen glitches2Repair Windows errors before they cause bigger problems3Scan for outdated or missing drivers - takes under a minuteQuick Recap
Best Value
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

