EC-Council Certified Ethical Hacker (CEH) v12System Hacking Phases and Attack TechniquesHard
An ethical hacker is conducting a penetration test against an organization with a strong endpoint detection and response (EDR) solution. They need to deploy a custom payload on a target Windows machine without being detected. To bypass signature-based EDR, they decide to encrypt their shellcode and then use a legitimate, signed executable (e.g., PowerShell) to decrypt and execute it in memory, without writing the payload to disk. What is this technique commonly referred to as?
- AFileless Malware
- BReflective DLL Injection
- CProcess Doppelgänging
- DAnti-Forensics
Show answer & explanationAnswer & explanation
Correct answer: A. Fileless Malware
The scenario describes executing malicious code (encrypted shellcode) directly in memory via a legitimate system tool (PowerShell), without leaving any persistent files on disk. This is the definition of 'Fileless Malware' or 'Living off the Land' (LotL) attacks, which are designed to evade traditional signature-based detection.
Why the other options are wrong
- B. Reflective DLL Injection is a specific method of injecting a DLL into a process's memory from a remote process or a local stub, but 'fileless malware' is the broader concept covering the described scenario.
- C. Process Doppelgänging is an advanced evasion technique involving transaction rollback to create a hidden process, which is more specific and complex than the described 'execute in memory without writing to disk' approach.
- D. Anti-Forensics is a general term for techniques to hinder forensic analysis, not a specific execution method.
Fileless Malware
Malicious software that operates entirely in system memory, leveraging legitimate tools and processes ('living off the land') to execute its payload without writing files to disk, making it difficult for traditional antivirus and EDR solutions to detect.
- Avoids disk-based signatures by executing in memory.
- Often uses PowerShell, WMI, or other legitimate scripting/system tools.
- Focuses on stealth and evasion of endpoint security solutions.
Memory trick: Evasion: Fileless for no disk, Obfuscation for code, Packing for compression, Polymorphism for change.