Reflective DLL Loading
Definition
A technique that loads a Windows DLL directly from memory without registering it with the OS loader. The DLL resolves its own imports and maps itself. Because no file is written to disk and no entry appears in the standard loaded-module list, it is a common method for staging payloads in memory.
- Platform
- Windows
- Mechanism
- DLL maps and resolves its own imports without the OS loader
- Disk footprint
- None, the file is never written to disk
- Detection challenge
- No entry in the standard loaded-module list
Common questions
If reflective DLL loading leaves no entry in the standard loaded-module list, how do investigators detect it?+
Investigators look for indirect signs such as memory regions with executable permissions that lack a backing file on disk, anomalies in a process's memory-mapped section list, or behavioural indicators, techniques that require live memory acquisition and analysis tools rather than standard module enumeration.
Why do attackers prefer reflective DLL loading over dropping a normal DLL file?+
Because no file touches disk, traditional file-based antivirus scanning and disk forensics find nothing to flag, and the technique avoids leaving a persistent artefact that would survive a reboot, making it attractive for staging payloads that only need to run in the current session.
Related terms
- LiME (Linux Memory Extractor)
- A loadable kernel module that acquires physical memory from Linux, macOS, and Android systems. It maps the physical address space and either...
- Order of Volatility
- The sequence in which digital evidence should be collected, ranked from most to least transient. Defined in RFC 3227. CPU registers and...
- Physical Memory Image
- A byte-for-byte copy of all installed RAM on a running system, acquired at the hardware or kernel level. Contains all data structures,...
- Process Injection
- A technique used by malware and attackers to execute code inside the address space of a legitimate running process. Common methods include...
- Volatility Framework
- An open-source memory forensics framework written in Python. It parses raw memory images using OS-specific symbol information to reconstruct kernel data structures...