What is Fileless Malware? Explained, with Examples
ID: c7eff295-254e-53ba-bbd0-09986be34037
STIX ID: report--c7eff295-254e-53ba-bbd0-09986be34037
Feed Name: Intezer Blog
An educational overview of fileless malware explaining how attackers use in-memory execution and living-off-the-land techniques (e.g., PowerShell/WMI) to evade file-based detection, with examples like Poweliks and POSHSPY, a breakdown of common attack stages, and the difficulties of distinguishing malicious from legitimate admin activity; it concludes with defensive guidance (behavioral EDR, patching, least privilege, application whitelisting, enhanced logging) and advocates automated memory forensics to quickly detect and contain in-memory threats.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
