Reflective Code Injection Attacks – An Overview for Incident Responders

Reflective code injection lets attackers execute code directly in process memory, leaving minimal file-system traces. This overview explains the technique on Windows and Linux, then covers detection methods for incident responders: VAD tree inspection, /proc analysis, RWX memory anomalies, suspicious system calls, and tools such as MemProcFS, Volatility and YARA.

Continue ReadingReflective Code Injection Attacks – An Overview for Incident Responders
Read more about the article DFIR on a Shoestring – Incident response for less
DFIR - Is it a cost you cant avoid?

DFIR on a Shoestring – Incident response for less

EDR and Forensics tools can be very expensive. This post looks at some cheap, or free, DFIR alternatives you absolutely should consider. Even if you have a good budget for high-end professional tools, it's worth building these into a toolbox you can use to solve problems or unexpected situations.

Continue ReadingDFIR on a Shoestring – Incident response for less
Read more about the article Incident Response Phases – Lessons Learned
PICERL - Common incident response process / framework

Incident Response Phases – Lessons Learned

Lessons Learned is the final phase of the incident response cycle. This is where you identify the root cause of the incident and any problems or issues you faced with the response. Your findings should always feed back into the planning phase. This keeps the cycle working and improving.

Continue ReadingIncident Response Phases – Lessons Learned
Read more about the article Memory analysis in incident response – never leave home without it
Memory analysis supports incident response in ways people never consider

Memory analysis in incident response – never leave home without it

Incident response is often a stressful, high-pressure situation. Responders are desperately trying to claw together information. All around them the world is collapsing. Furthermore, everything important seems to be deleted…

Continue ReadingMemory analysis in incident response – never leave home without it