METHODS AND TOOLS FOR FORENSIC MEMORY ANALYSIS TO DETECT HIDDEN PROCESSES IN COMPUTER SYSTEMS

Authors

DOI:

https://doi.org/10.28925/2663-4023.2026.34.1256

Keywords:

memory forensics, hidden processes, Reflective DLL Injection, Meterpreter, Volatility 3, Magnet RESPONSE, fileless attacks, Windows 11, VAD tree, MITRE ATT&CK, digital forensics

Abstract

The article addresses the problem of detecting hidden processes and injected malicious code in the volatile memory of computer systems running Microsoft Windows 11. The relevance of the research is driven by the rapid growth of fileless attacks, which fully unfold in RAM and leave no traces accessible to classical antivirus and EDR monitoring tools. According to industry reports, the volume of cyberattacks increased by 30 % in Q2 2024, with a significant share constituted by fileless and memory-resident campaigns. The aim of the article is to formalise a methodology for detecting hidden processes through analysis of memory structures — Virtual Address Descriptor (VAD) tree and page organisation — using the Volatility 3 framework with subsequent external validation of the obtained results. The paper systematises the theoretical foundations of Windows virtual memory organisation, performs a comparative analysis of six memory acquisition tools and four analysis frameworks, and traces the evolution of code-hiding techniques. The proposed methodology is designed as a sequential six-stage process: preparation, volatile data acquisition, triage, deep analysis (in three parallel branches: process analysis, memory analysis, and network analysis), cross-verification through external cyberintelligence platforms, and reporting with chain-of-custody documentation. The methodology is integrated with NIST SP 800-86, IETF RFC 3227, and MITRE ATT&CK standards. Experimental verification of the methodology has been performed on a controlled attack scenario using the Metasploit Meterpreter framework with subsequent migration of the malicious code into the address space of the legitimate Windows 11 explorer.exe process via the Reflective DLL Injection technique (T1055.001 in MITRE ATT&CK classification). A robust set of compromise indicators has been identified: two private RWX memory regions, a characteristic x86-64 shellcode prologue with the typical PEB-traversal pattern through the GS segment, the asymmetry of the VAD tree with the absence of file-on-disk linkage for the anomalous regions, and a hardcoded address of the command-and-control server. Independent validation through the VirusTotal platform has confirmed the artefact's attribution to the shellcode/marte family with a detection rate of 17 out of 62 antivirus engines. Comparative analysis with the reference (clean) dump has unequivocally proven that the detected anomalies result from the simulated attack rather than background system activity. The detected artefacts are mapped onto six MITRE ATT&CK matrix techniques: T1105, T1204.002, T1055.001, T1620, T1562.001, and T1071.001, ensuring compatibility of conclusions with the international incident response practice. The scientific novelty consists in the formalisation of a generalised methodology for detecting hidden processes that integrates collection, triage, deep analysis, cross-verification, and reporting stages with explicit MITRE ATT&CK mapping, applied to modern Windows 11 systems. The practical significance of the work lies in the methodology's readiness for direct application in cybersecurity training at bachelor and master levels, in commercial and governmental SOC incident response practice, and as a methodological basis for further research in volatile memory forensics. Prospective research directions include extending the methodology to privilege escalation and credential dumping scenarios, adaptation to Linux and macOS platforms, integration with EDR platforms, and the application of deep learning methods for automated classification of detected artefacts.

Downloads

Download data is not yet available.

References

Pillai, R., Talreja, S. R., & Pamarthi, V. (2024). Memory forensics using the Volatility framework: A structured approach for detecting fileless malware. In 2024 International Conference on Innovative Computing, Intelligent Communication and Smart Electrical Systems (ICSES). IEEE. https://ieeexplore.ieee.org/document/11323993

Check Point Research. (2024). Q2 2024 cyber attacks report. Check Point Software Technologies. https://blog.checkpoint.com/research/

MITRE ATT&CK. (n.d.). Process injection (Technique T1055). MITRE. https://attack.mitre.org/techniques/T1055/

Cyber Forensics Academy. (2025). Volatility framework: Complete memory forensics guide. https://www.cyberforensicacademy.com/blog/volatility-framework-complete-memory-forensics-guide

Dolan-Gavitt, B. (2007). The VAD tree: A process-eye view of physical memory. Digital Investigation, 4(1), 62–64. https://doi.org/10.1016/j.diin.2007.06.008

Fewer, S. (2008). Reflective DLL injection. Harmony Security White Paper. https://www.harmonysecurity.com/files/HS-P005_ReflectiveDllInjection.pdf

Microsoft Defender Research Team. (2025). Detecting reflective DLL loading with Windows Defender ATP. Microsoft Security Blog. Microsoft. https://www.microsoft.com/en-us/security/blog/2017/11/13/detecting-reflective-dll-loading-with-windows-defender-atp/

Dehfouli, Y., & Habibi Lashkari, A. (2025). Memory analysis for malware detection: A comprehensive survey using the OSCAR methodology. ACM Computing Surveys. https://doi.org/10.1145/3764580

Odeh, A., Taleb, A. A., Alhajahjeh, T., & Navarro, F. (2025). Advanced memory forensics for malware classification with deep learning algorithms. Cluster Computing, 28(6). https://doi.org/10.1007/s10586-025-05104-7

Case, A. (2025). Analysis of sedexp Linux malware: Memory-only rootkit and anti-forensics techniques. From the Source 2025. The Volatility Foundation. https://volatilityfoundation.org/from-the-source-2025/

TrustedSec. (2024). Loading DLLs reflections. TrustedSec Blog. https://trustedsec.com/blog/loading-dlls-reflections

Cynet. (2026). Process injection techniques. https://www.cynet.com/attack-techniques-hands-on/process-injection-techniques/

Pen Test Partners. (2024). Using Volatility for advanced memory forensics. Pen Test Partners Blog. https://www.pentestpartners.com/security-blog/using-volatility-for-advanced-memory-forensics/

Solomon, D. A., Russinovich, M. E., Ionescu, A., & Yosifovich, P. (2017). Windows internals. Part 1: System architecture, processes, threads, memory management, and more (7th ed.). Microsoft Press.

Faiz, M. N., & Prabowo, W. A. (2019). Comparison of acquisition software for digital forensics purposes. Kinetik, 4(1), 37–44. https://doi.org/10.22219/kinetik.v4i1.687

Volatility Foundation. (n.d.). Volatility 3 documentation: Plugin reference. https://volatility3.readthedocs.io/en/latest/

VirusTotal. (2025). Public API and scanning engine documentation. https://docs.virustotal.com/

Rapid7. (2025). Metasploit Framework: Documentation and module reference. https://docs.metasploit.com/

Magnet Forensics. (2024). Magnet RESPONSE: Free incident response tool. https://www.magnetforensics.com/resources/magnet-response/

MITRE Corporation. (2024). Process injection: Dynamic-link library injection (Technique T1055.001). MITRE ATT&CK. https://attack.mitre.org/techniques/T1055/001/

Microsoft. (2024). Strings v2.54. Windows Sysinternals. https://learn.microsoft.com/en-us/sysinternals/downloads/strings

Said Hamed, A. S., & Dewangan, O. (2025). Digital forensic: Techniques, challenges, and future direction. International Journal for Research in Applied Science and Engineering Technology. https://doi.org/10.22214/ijraset.2025.71562

Downloads


Abstract views: 4

Published

2026-09-24

How to Cite

Zavalii, S., & Koval, V. (2026). METHODS AND TOOLS FOR FORENSIC MEMORY ANALYSIS TO DETECT HIDDEN PROCESSES IN COMPUTER SYSTEMS. Electronic Professional Scientific Journal «Cybersecurity: Education, Science, Technique», 2(34), 225–240. https://doi.org/10.28925/2663-4023.2026.34.1256