Registry keys, hidden processes, known strings and other indicators residing in memory can all help with the early identification of malware infections, especially fileless varieties. This talk will look at how relevant structures are stored in memory, along with a high level look at Windows memory management and a discussion of the pros/cons of some possible methods for searching RAM.
About Peter Cowman
Final year Ethical Hacking student at Abertay University. Interested in malware and memory analysis.