
Sign up to save your podcasts
Or
In this podcast episode, we talk about Linux's `memfd` – a virtual file system allowing the creation of anonymous memory areas for shared memory or temporary data storage. Threat actors exploit `memfd` for fileless malware attacks, as its memory areas exist only in RAM, evading traditional file-based detection methods. Join me as I `memfd` as a forensic artifact, its implications in DFIR, and strategies for detecting its abuse.
4.9
6161 ratings
In this podcast episode, we talk about Linux's `memfd` – a virtual file system allowing the creation of anonymous memory areas for shared memory or temporary data storage. Threat actors exploit `memfd` for fileless malware attacks, as its memory areas exist only in RAM, evading traditional file-based detection methods. Join me as I `memfd` as a forensic artifact, its implications in DFIR, and strategies for detecting its abuse.
2,000 Listeners
369 Listeners
639 Listeners
370 Listeners
185 Listeners
1,016 Listeners
320 Listeners
414 Listeners
7,965 Listeners
188 Listeners
315 Listeners
73 Listeners
134 Listeners
43 Listeners
168 Listeners