Skip to content

Memory-Resident Malware

Definition

Malicious code that executes entirely in RAM and writes no files to disk. Fileless malware, PowerShell-based loaders, and certain rootkits fall into this category. A shutdown destroys the only copy; live memory acquisition is the sole means of capturing it.

Also called
Fileless malware
Storage location
RAM only, no disk write
Examples
PowerShell loaders, certain rootkits
Capture method
Live memory acquisition only
Destroyed by
System shutdown

Common questions

Why is shutting down a suspect machine risky if memory-resident malware is suspected?+

Because the malicious code exists only in volatile RAM, powering the machine off erases the only copy along with any evidence of what it was doing. Standard incident response procedure is to image memory before any shutdown or reboot when fileless activity is suspected.

Why does traditional disk forensics often miss this kind of malware entirely?+

Disk imaging and file-system analysis only capture what was written to storage, and memory-resident malware by design never writes an executable to disk. Investigators need live acquisition tools that dump RAM contents, then analyze that dump for injected code, suspicious process memory, or command-line artifacts.

Related terms

Chain of Custody
The documented chronological record of who collected, handled, transferred, and examined a piece of evidence. For digital evidence, chain of custody includes...
Live Response
The process of collecting evidence and triage data from a running system without first powering it down. Preserves volatile artefacts that would...
Non-Volatile Data
Data that persists without power, such as files on a hard disk, SSD, or optical media, and data in non-volatile memory chips....
RFC 3227
Guidelines for Evidence Collection and Archiving, published by the IETF in February 2002. It defines the order of volatility, the documentation requirements...
Volatile Data
Any digital information that is lost when power is removed or the system state changes. Examples include RAM contents, CPU register values,...

Explained in

Your journey to becoming a forensic professional starts here.

Practice with mock tests, learn from structured notes, and get your questions answered by a global forensic community, all in one place.