Memory-Resident Malware
Definition
Malicious code that executes entirely in RAM and writes no files to disk. Fileless malware, PowerShell-based loaders, and certain rootkits fall into this category. A shutdown destroys the only copy; live memory acquisition is the sole means of capturing it.
- Also called
- Fileless malware
- Storage location
- RAM only, no disk write
- Examples
- PowerShell loaders, certain rootkits
- Capture method
- Live memory acquisition only
- Destroyed by
- System shutdown
Common questions
Why is shutting down a suspect machine risky if memory-resident malware is suspected?+
Because the malicious code exists only in volatile RAM, powering the machine off erases the only copy along with any evidence of what it was doing. Standard incident response procedure is to image memory before any shutdown or reboot when fileless activity is suspected.
Why does traditional disk forensics often miss this kind of malware entirely?+
Disk imaging and file-system analysis only capture what was written to storage, and memory-resident malware by design never writes an executable to disk. Investigators need live acquisition tools that dump RAM contents, then analyze that dump for injected code, suspicious process memory, or command-line artifacts.
Related terms
- Chain of Custody
- The documented chronological record of who collected, handled, transferred, and examined a piece of evidence. For digital evidence, chain of custody includes...
- Live Response
- The process of collecting evidence and triage data from a running system without first powering it down. Preserves volatile artefacts that would...
- Non-Volatile Data
- Data that persists without power, such as files on a hard disk, SSD, or optical media, and data in non-volatile memory chips....
- RFC 3227
- Guidelines for Evidence Collection and Archiving, published by the IETF in February 2002. It defines the order of volatility, the documentation requirements...
- Volatile Data
- Any digital information that is lost when power is removed or the system state changes. Examples include RAM contents, CPU register values,...