A security analyst suspects, based on the telemetry observed so far, that the latest attack on a company machine is memory-resident.
Which action must the analyst take next to confirm this suspicion?
Memory-resident malware exists in volatile system memory, so acquiring a memory dump before rebooting or otherwise altering the host preserves the evidence needed to identify malicious processes, injected code, and other in-memory artifacts. Memory dumps can be analyzed with forensic/debugging tools such as WinDbg.
Community Discussion