Reflective Code Injection Attacks – An Overview for Incident Responders

Reflective code injection lets attackers execute code directly in process memory, leaving minimal file-system traces. This overview explains the technique on Windows and Linux, then covers detection methods for incident responders: VAD tree inspection, /proc analysis, RWX memory anomalies, suspicious system calls, and tools such as MemProcFS, Volatility and YARA.

Continue ReadingReflective Code Injection Attacks – An Overview for Incident Responders
Read more about the article DFIR on a Shoestring – Incident response for less
DFIR - Is it a cost you cant avoid?

DFIR on a Shoestring – Incident response for less

EDR and Forensics tools can be very expensive. This post looks at some cheap, or free, DFIR alternatives you absolutely should consider. Even if you have a good budget for high-end professional tools, it's worth building these into a toolbox you can use to solve problems or unexpected situations.

Continue ReadingDFIR on a Shoestring – Incident response for less