Fileless malware and in-memory threats are getting harder to catch. They live in system memory, leave almost no traces on disk and exploit legitimate tools to move quietly through systems. In this presentation, Areg shares practical techniques for uncovering these threats through deep analysis of low-level Windows artifacts like event logs, registry hives, memory snapshots and WMI activity to reveal indicators of compromise and lateral movement patterns.
Event: BSIDES Armenia
Find the shadow, hunting advanced malware
·1 min·

