5.3 Malware Detection, Memory Forensics, and Eradication Strategies
Key Takeaways
Indicators of Compromise (IOCs) represent reactive, static forensic artifacts (hashes, IPs, domains), whereas Indicators of Attack (IOAs) detect proactive adversary behaviors and tactics in real time.
Memory acquisition must occur prior to powering down or rebooting to preserve volatile artifacts under RFC 3227, utilizing kernel-level tools like WinPmem, LiME, or FTK Imager.
The Volatility framework identifies process anomalies using pstree, uncovers DKOM-unlinked rootkit processes by comparing psscan to pslist, and identifies injected code via malfind.
Adversaries establish persistence via registry Run keys, scheduled tasks, Windows services, DLL search order hijacking, and stealthy WMI permanent event subscriptions (__EventFilter, __EventConsumer, __FilterToConsumerBinding).
Permanent eradication requires terminating entire process trees, purging persistence artifacts, sinkholing C2 domains, conducting enterprise YARA sweeps, and restoring clean systems from validated offline backups.
Malware Detection, Memory Forensics, and Eradication Strategies
When a malware intrusion breaches enterprise defenses, incident handlers must rapidly detect malicious artifacts, investigate compromised host memory, and systematically eradicate adversary footholds. Merely deleting an infected file is rarely sufficient; modern threats embed persistence mechanisms deep within the operating system and execute code directly within volatile memory. A certified incident handler must master host and network telemetry, execute forensically sound memory investigations, identify stealthy persistence vectors, and apply structured eradication workflows to ensure permanent remediation.
Indicators of Compromise (IOCs) vs. Indicators of Attack (IOAs)
Effective threat detection relies on correlating both reactive and proactive telemetry across enterprise infrastructure:
- Indicators of Compromise (IOCs): Forensic artifacts identified after an intrusion, representing reactive evidence of compromise. IOCs include static cryptographic file hashes (MD5, SHA-256), known malicious IP addresses, Command-and-Control (C2) domain names, specific file paths, and hardcoded mutex names. While IOCs provide concrete matching criteria for automated SIEM and firewall rules, they are easily rendered obsolete when adversaries recompile binaries or rotate infrastructure.
- Indicators of Attack (IOAs): Proactive, behavioral telemetry focused on adversary intent, tradecraft, and execution tactics in real time, independent of specific binary hashes or IP addresses. IOAs identify suspicious behavior, such as a Microsoft Word process spawning
cmd.exeorpowershell.exe, unauthorized dumping of the Local Security Authority Subsystem Service (LSASS) memory, rapid mass file modification indicating ransomware, or anomalous Kerberos ticket requests (Kerberoasting). IOAs answer what the adversary is attempting to achieve rather than what specific tool they dropped.
Memory Forensics Fundamentals and Volatility Analysis
Volatile system memory (RAM) is the most perishable digital evidence source under the RFC 3227 Order of Volatility. Some critical artifacts—such as injected code, process memory, and cryptographic material—may exist only in RAM, while sockets and process activity can also leave partial traces in logs or telemetry. Power loss destroys the live memory state.
Memory Acquisition Tools
Incident handlers acquire physical RAM before initiating destructive containment:
- WinPmem: An open-source, kernel-driver acquisition utility that captures physical memory on Windows endpoints without crashing production systems.
- LiME (Linux Memory Extractor): A Loadable Kernel Module (LKM) allowing forensically sound volatile memory acquisition from live Linux systems, bypassing user-space limitations.
- FTK Imager (CLI/GUI): A standard forensic utility capable of capturing complete physical RAM images along with the system pagefile (
pagefile.sys).
Volatility Framework Analysis
Once a raw memory image is secured, analysts deploy the Volatility framework (Volatility 2 / Volatility 3) to dissect operating system data structures:
windows.pslist.PsList: Traverses the active process doubly-linked list (ActiveProcessLinks) in kernel space to display running processes, start times, and process IDs (PIDs).windows.pstree.PsTree: Reconstructs the hierarchical parent-child process tree based on Parent Process IDs (PPID), exposing anomalous lineages (e.g.,svchost.exerunning withoutservices.exeas its parent, or web server daemons spawning command shells).windows.psscan.PsScan: Scans physical memory pool tags for unlinkedEPROCESSstructures. By comparingpsscanagainstpslist, analysts uncover stealthy rootkits that used Direct Kernel Object Manipulation (DKOM) to unlink malicious processes fromActiveProcessLinks.windows.malfind.Malfind: Identifies injected code and DLLs within user-mode process address spaces.malfindscans Virtual Address Descriptors (VADs) for memory pages flagged withPAGE_EXECUTE_READWRITE(RWX) permissions and inspects the initial bytes for shellcode or embedded PE headers (0x5A4D/MZ).windows.dlllist.DllList: Enumerates loaded DLLs for each running process, identifying unsigned or misplaced libraries.windows.netscan.NetScan: Carves active and closed TCP/UDP network connections, listening sockets, and remote IP addresses directly from memory pools.windows.yarascan.YaraScan: Executes YARA pattern-matching rules across kernel memory and process address spaces to locate known malware signatures resident in RAM.
Detecting Adversary Persistence Mechanisms
To survive system reboots, malware establishes persistence across multiple operating system layers:
- Registry Run and RunOnce Keys: Adversaries add values under
HKLM\Software\Microsoft\Windows\CurrentVersion\Run,HKCU\Software\Microsoft\Windows\CurrentVersion\Run, andWinlogon\Userinitto execute payloads whenever a user authenticates. - Startup Folders: Placing shortcuts or executables directly into
%APPDATA%\Microsoft\Windows\Start Menu\Programs\Startupexecutes code upon user logon. - Scheduled Tasks and Services:
- Scheduled Tasks: Created via
schtasks.exe /createor Task Scheduler, executing binaries periodically or upon specific system triggers. - Windows Services: Malware registers rogue background services (
sc.exe createor modifyingHKLM\SYSTEM\CurrentControlSet\Services) to run with elevatedNT AUTHORITY\SYSTEMprivileges upon boot.
- Scheduled Tasks: Created via
- WMI Permanent Event Subscriptions: A stealthy, fileless persistence mechanism maintained in the WMI repository (
OBJECTS.DATA). It consists of three components: an__EventFilter(a WQL query detecting trigger events like system startup or user logon), an__EventConsumer(an action component such asCommandLineEventConsumerexecuting scripts), and a__FilterToConsumerBindinglinking the filter to the consumer. - DLL Side-Loading and Search Order Hijacking: Attackers exploit the Windows DLL search order (Application Directory -> System32 -> System -> Windows -> Current Directory -> PATH). By placing a malicious DLL named legitimately (e.g.,
version.dll) in the same directory as a trusted executable, the application loads the malicious DLL upon execution.
Structured Containment and Eradication Strategies
Eradication must follow a coordinated sequence to prevent malware watchdog processes from respawning components:
- Process Tree Termination: Handlers map related processes, persistence, services, and watchdog behavior, then use an approved EDR or operating-system containment sequence. Killing a visible process tree alone may trigger respawn or destroy volatile evidence, so timing follows the investigation and containment plan.
- Persistence Deletion: Systematically purge identified persistence mechanisms: deleting rogue registry autorun entries, removing scheduled tasks (
schtasks /delete), stopping and deleting unauthorized services (sc stopfollowed bysc delete), and unbinding WMI event subscriptions (Get-CimInstance). - Perimeter and DNS Remediation: Block identified C2 IP addresses on perimeter firewalls, update proxy blacklists, and redirect malicious domains to an internal DNS sinkhole to identify other compromised hosts.
- Enterprise-Wide Host Scans: Deploy verified YARA rules and IOC hashes across enterprise endpoints via EDR or orchestration scripts to verify eradication and uncover lateral infections.
- Clean System Recovery: Restore compromised servers from verified, immutable offline backups created prior to the initial point of compromise (dwell time validation). In incidents involving rootkits or bootkits, perform clean operating system reinstalls, re-baseline administrative credentials, and implement continuous endpoint telemetry during recovery.
An incident responder analyzes a physical memory image using the Volatility framework to investigate suspected code injection. Which Volatility plugin specifically scans Virtual Address Descriptors (VADs) to locate memory sections marked with PAGE_EXECUTE_READWRITE permissions and checks for unmapped executable code or injected PE headers?
windows.netscan
windows.dlllist
windows.malfind
windows.pslist
An adversary establishes fileless persistence on a Windows server. Even after the initial dropper executable is deleted, malicious PowerShell commands execute automatically every time the server reboots. Forensic inspection reveals a WQL query listening for system startup events tied to a script execution object in the WMI repository. Which persistence mechanism was configured?
DLL Search Order Hijacking
Userinit Registry Modification
Unquoted Service Path Exploitation
WMI Permanent Event Subscription
A malicious actor places a rogue dynamic link library named version.dll into the application installation directory of a trusted, digitally signed third-party utility. When an administrator launches the signed utility, the application loads the rogue DLL from its current folder instead of loading the legitimate system library from C:\Windows\System32. Which attack mechanism has occurred?
DLL search order hijacking (DLL side-loading)
Direct Kernel Object Manipulation (DKOM)
Dynamic Domain Generation Algorithm (DGA)
Master Boot Record bootkit infection
Sections you finish are checked off in the contents.