Illustration of five surfboards standing upright on a beach with palm trees. Each has a command line icon. The text reads, Detect Suspicious Fileless Process Execution. A logo with the word upwind is at the top. The background is a gradient blue sky.

Detect Suspicious Fileless Process Execution

Denise Ashur March 04, 2024

Detect Suspicious Fileless Process Execution

We’re excited to announce the ability to monitor and detect malicious “fileless execution” events. This capability enables alerting when a process is executed without using an executable file on a disk or file system.

Fileless Execution

The action of a process being executed using an in-memory executable file is a common defense evasion technique used by malicious actors to avoid writing an executable or new code to the disk, allowing an attacker to avoid being detected by file system scanning.

In addition, in many cases, security & DevOps teams already deploy their containers’ root filesystem in read-only mode. This theoretically prevents an attacker from downloading their malware executable to disk. However, sophisticated attackers use fileless malware and execute commands directly in memory.

Although this is a common malware technique, there are also some legitimate use cases for fileless execution, such as a just-in-time (JIT) compiler writing compiled code to memory and executing it from memory.

fileless-detection-example-1024x654

Indicators of Compromise

Upwind’s fileless execution detection is intended to find fileless malware, which is a form of attack that does not require the installation of new executables on a system, although attackers will need to access the environment. Common methods of fileless execution attacks include compromising native tools, memory-only malware, fileless ransomware and stolen credentials.

In a fileless execution attack, attackers commonly do the following:

  1. Exploit a vulnerability and gain remote access to an environment
  2. Obtain credentials for the compromised environment, allowing the attacker to traverse into other systems
  3. Modify the registry and establish a backdoor.
  4. Access data and exfiltrate it out to the network.

Upwind leverages runtime data to rapidly identify unusual fileless executions and immediately alert you to suspicious activity. Read more about fileless execution detections in the Upwind Documentation Center.

Contents

Further Reading

What IAM Sees That You Don't

What IAM Sees That You Don’t

Every IAM policy you write depends on condition keys - they're the precision layer that turns "can call S3" into "can call S3 only from our VPC, using our identity, on resources we own." They're the backbone of least-privilege, data perimeters, and SCP guardrails. But here's the thing: for every request, the IAM engine assembles…
Let Me Speak to Your Manager (Account)

Let Me Speak to Your Manager (Account)

The management account is the most privileged account in any AWS Organization. It controls SCPs, creates and deletes member accounts, manages IAM Identity Center, and is itself exempt from SCPs. Getting its 12-digit account ID is the first step in targeting it. The documented way to get it is organizations:DescribeOrganization - but security-conscious environments restrict…
Configuration-Focus

Introducing the new Configurations experience in Upwind

Compliance should not be a fire drill! Ask a security team how audit season goes and you will often hear a version of the same story. Someone pulls a list of cloud accounts. Someone else exports findings into a spreadsheet that is already outdated by the time it is shared. Screenshots get pasted into a…
Add the Upwind RSS Feed to Slack
Connect the Upwind RSS Feed to your Slack.
Follow the how-to here.
Threat RSS
Add the Upwind RSS Feed to Slack
Connect the Upwind RSS Feed to your Slack.
Follow the how-to here.
Main RSS