5.3 Malware Detection, Memory Forensics, and Eradication Strategies

Key Takeaways

  • Indicators of Compromise (IOCs) represent reactive, static forensic artifacts (hashes, IPs, domains), whereas Indicators of Attack (IOAs) detect proactive adversary behaviors and tactics in real time.

  • Memory acquisition must occur prior to powering down or rebooting to preserve volatile artifacts under RFC 3227, utilizing kernel-level tools like WinPmem, LiME, or FTK Imager.

  • The Volatility framework identifies process anomalies using pstree, uncovers DKOM-unlinked rootkit processes by comparing psscan to pslist, and identifies injected code via malfind.

  • Adversaries establish persistence via registry Run keys, scheduled tasks, Windows services, DLL search order hijacking, and stealthy WMI permanent event subscriptions (__EventFilter, __EventConsumer, __FilterToConsumerBinding).

  • Permanent eradication requires terminating entire process trees, purging persistence artifacts, sinkholing C2 domains, conducting enterprise YARA sweeps, and restoring clean systems from validated offline backups.

Last updated: October 2026

Malware Detection, Memory Forensics, and Eradication Strategies

When a malware intrusion breaches enterprise defenses, incident handlers must rapidly detect malicious artifacts, investigate compromised host memory, and systematically eradicate adversary footholds. Merely deleting an infected file is rarely sufficient; modern threats embed persistence mechanisms deep within the operating system and execute code directly within volatile memory. A certified incident handler must master host and network telemetry, execute forensically sound memory investigations, identify stealthy persistence vectors, and apply structured eradication workflows to ensure permanent remediation.

Indicators of Compromise (IOCs) vs. Indicators of Attack (IOAs)

Effective threat detection relies on correlating both reactive and proactive telemetry across enterprise infrastructure:

  • Indicators of Compromise (IOCs): Forensic artifacts identified after an intrusion, representing reactive evidence of compromise. IOCs include static cryptographic file hashes (MD5, SHA-256), known malicious IP addresses, Command-and-Control (C2) domain names, specific file paths, and hardcoded mutex names. While IOCs provide concrete matching criteria for automated SIEM and firewall rules, they are easily rendered obsolete when adversaries recompile binaries or rotate infrastructure.
  • Indicators of Attack (IOAs): Proactive, behavioral telemetry focused on adversary intent, tradecraft, and execution tactics in real time, independent of specific binary hashes or IP addresses. IOAs identify suspicious behavior, such as a Microsoft Word process spawning cmd.exe or powershell.exe, unauthorized dumping of the Local Security Authority Subsystem Service (LSASS) memory, rapid mass file modification indicating ransomware, or anomalous Kerberos ticket requests (Kerberoasting). IOAs answer what the adversary is attempting to achieve rather than what specific tool they dropped.

Memory Forensics Fundamentals and Volatility Analysis

Volatile system memory (RAM) is the most perishable digital evidence source under the RFC 3227 Order of Volatility. Some critical artifacts—such as injected code, process memory, and cryptographic material—may exist only in RAM, while sockets and process activity can also leave partial traces in logs or telemetry. Power loss destroys the live memory state.

Memory Acquisition Tools

Incident handlers acquire physical RAM before initiating destructive containment:

  • WinPmem: An open-source, kernel-driver acquisition utility that captures physical memory on Windows endpoints without crashing production systems.
  • LiME (Linux Memory Extractor): A Loadable Kernel Module (LKM) allowing forensically sound volatile memory acquisition from live Linux systems, bypassing user-space limitations.
  • FTK Imager (CLI/GUI): A standard forensic utility capable of capturing complete physical RAM images along with the system pagefile (pagefile.sys).

Volatility Framework Analysis

Once a raw memory image is secured, analysts deploy the Volatility framework (Volatility 2 / Volatility 3) to dissect operating system data structures:

  • windows.pslist.PsList: Traverses the active process doubly-linked list (ActiveProcessLinks) in kernel space to display running processes, start times, and process IDs (PIDs).
  • windows.pstree.PsTree: Reconstructs the hierarchical parent-child process tree based on Parent Process IDs (PPID), exposing anomalous lineages (e.g., svchost.exe running without services.exe as its parent, or web server daemons spawning command shells).
  • windows.psscan.PsScan: Scans physical memory pool tags for unlinked EPROCESS structures. By comparing psscan against pslist, analysts uncover stealthy rootkits that used Direct Kernel Object Manipulation (DKOM) to unlink malicious processes from ActiveProcessLinks.
  • windows.malfind.Malfind: Identifies injected code and DLLs within user-mode process address spaces. malfind scans Virtual Address Descriptors (VADs) for memory pages flagged with PAGE_EXECUTE_READWRITE (RWX) permissions and inspects the initial bytes for shellcode or embedded PE headers (0x5A4D / MZ).
  • windows.dlllist.DllList: Enumerates loaded DLLs for each running process, identifying unsigned or misplaced libraries.
  • windows.netscan.NetScan: Carves active and closed TCP/UDP network connections, listening sockets, and remote IP addresses directly from memory pools.
  • windows.yarascan.YaraScan: Executes YARA pattern-matching rules across kernel memory and process address spaces to locate known malware signatures resident in RAM.

Detecting Adversary Persistence Mechanisms

To survive system reboots, malware establishes persistence across multiple operating system layers:

  • Registry Run and RunOnce Keys: Adversaries add values under HKLM\Software\Microsoft\Windows\CurrentVersion\Run, HKCU\Software\Microsoft\Windows\CurrentVersion\Run, and Winlogon\Userinit to execute payloads whenever a user authenticates.
  • Startup Folders: Placing shortcuts or executables directly into %APPDATA%\Microsoft\Windows\Start Menu\Programs\Startup executes code upon user logon.
  • Scheduled Tasks and Services:
    • Scheduled Tasks: Created via schtasks.exe /create or Task Scheduler, executing binaries periodically or upon specific system triggers.
    • Windows Services: Malware registers rogue background services (sc.exe create or modifying HKLM\SYSTEM\CurrentControlSet\Services) to run with elevated NT AUTHORITY\SYSTEM privileges upon boot.
  • WMI Permanent Event Subscriptions: A stealthy, fileless persistence mechanism maintained in the WMI repository (OBJECTS.DATA). It consists of three components: an __EventFilter (a WQL query detecting trigger events like system startup or user logon), an __EventConsumer (an action component such as CommandLineEventConsumer executing scripts), and a __FilterToConsumerBinding linking the filter to the consumer.
  • DLL Side-Loading and Search Order Hijacking: Attackers exploit the Windows DLL search order (Application Directory -> System32 -> System -> Windows -> Current Directory -> PATH). By placing a malicious DLL named legitimately (e.g., version.dll) in the same directory as a trusted executable, the application loads the malicious DLL upon execution.

Structured Containment and Eradication Strategies

Eradication must follow a coordinated sequence to prevent malware watchdog processes from respawning components:

  1. Process Tree Termination: Handlers map related processes, persistence, services, and watchdog behavior, then use an approved EDR or operating-system containment sequence. Killing a visible process tree alone may trigger respawn or destroy volatile evidence, so timing follows the investigation and containment plan.
  2. Persistence Deletion: Systematically purge identified persistence mechanisms: deleting rogue registry autorun entries, removing scheduled tasks (schtasks /delete), stopping and deleting unauthorized services (sc stop followed by sc delete), and unbinding WMI event subscriptions (Get-CimInstance).
  3. Perimeter and DNS Remediation: Block identified C2 IP addresses on perimeter firewalls, update proxy blacklists, and redirect malicious domains to an internal DNS sinkhole to identify other compromised hosts.
  4. Enterprise-Wide Host Scans: Deploy verified YARA rules and IOC hashes across enterprise endpoints via EDR or orchestration scripts to verify eradication and uncover lateral infections.
  5. Clean System Recovery: Restore compromised servers from verified, immutable offline backups created prior to the initial point of compromise (dwell time validation). In incidents involving rootkits or bootkits, perform clean operating system reinstalls, re-baseline administrative credentials, and implement continuous endpoint telemetry during recovery.
Loading diagram...
Memory Forensics and Malware Eradication Workflow
Test Your Knowledge

An incident responder analyzes a physical memory image using the Volatility framework to investigate suspected code injection. Which Volatility plugin specifically scans Virtual Address Descriptors (VADs) to locate memory sections marked with PAGE_EXECUTE_READWRITE permissions and checks for unmapped executable code or injected PE headers?

A

windows.netscan

B

windows.dlllist

C

windows.malfind

D

windows.pslist

Test Your Knowledge

An adversary establishes fileless persistence on a Windows server. Even after the initial dropper executable is deleted, malicious PowerShell commands execute automatically every time the server reboots. Forensic inspection reveals a WQL query listening for system startup events tied to a script execution object in the WMI repository. Which persistence mechanism was configured?

A

DLL Search Order Hijacking

B

Userinit Registry Modification

C

Unquoted Service Path Exploitation

D

WMI Permanent Event Subscription

Test Your Knowledge

A malicious actor places a rogue dynamic link library named version.dll into the application installation directory of a trusted, digitally signed third-party utility. When an administrator launches the signed utility, the application loads the rogue DLL from its current folder instead of loading the legitimate system library from C:\Windows\System32. Which attack mechanism has occurred?

A

DLL search order hijacking (DLL side-loading)

B

Direct Kernel Object Manipulation (DKOM)

C

Dynamic Domain Generation Algorithm (DGA)

D

Master Boot Record bootkit infection

Sections you finish are checked off in the contents.