Hunting In Memory
ID: f0f94c9c-82db-5d9c-9950-c2d6ff3d1007
STIX ID: report--f0f94c9c-82db-5d9c-9950-c2d6ff3d1007
Feed Name: Elastic Security Labs
This report explains common in-memory attacker techniques (shellcode injection, reflective DLL injection, memory-module loading, process hollowing, module overwriting, and Gargoyle ROP/APC) and outlines practical hunting and detection methods focused on thread start addresses, memory protections, and image vs. private sections. It highlights a low-noise PowerShell approach (Get-InjectedThreads) and enterprise-scale capabilities to surface injected threads, while discussing sources of false positives such as security product injections, JIT-compiled code, and DRM/packed applications. The emphasis is on operationalizing high-fidelity, scalable detection for fileless and memory-resident threats.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
