logo

Hunting In Memory

ID: f0f94c9c-82db-5d9c-9950-c2d6ff3d1007

STIX ID: report--f0f94c9c-82db-5d9c-9950-c2d6ff3d1007

Feed Name: Elastic Security Labs

Date Published: 2022-06-21

Date Updated: 2026-04-27

...
...

This report explains common in-memory attacker techniques (shellcode injection, reflective DLL injection, memory-module loading, process hollowing, module overwriting, and Gargoyle ROP/APC) and outlines practical hunting and detection methods focused on thread start addresses, memory protections, and image vs. private sections. It highlights a low-noise PowerShell approach (Get-InjectedThreads) and enterprise-scale capabilities to surface injected threads, while discussing sources of false positives such as security product injections, JIT-compiled code, and DRM/packed applications. The emphasis is on operationalizing high-fidelity, scalable detection for fileless and memory-resident threats.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.