3 ms·
I would assume they could also dump memory, i.e. `/dev/mem`. Agreed they would need to also do frequent memory snapshots, but lots of malware will also run in
by nshelly 2y ago
I would assume they could also dump memory, i.e. `/dev/mem`. Agreed they would need to also do frequent memory snapshots, but lots of malware will also run in the background waiting indefinitely, and often as the same name as common Linux processes but different hashes.
- qeternity 2y agoYou would need an agent to do this. Cloning EBS won’t dump memory.
- stefan_ 2y agoThe people who have /dev/mem and run this garbage must form a complete overlapping circle.
- fullspectrumdev 2y agoEven if it’s sitting in the background under a spoofed process name, it can be caught with memory dumps. Memory dumps are obnoxiously useful for detecting stealthy malware, especially if you do the memory dumps from the hypervisor instead of from the VM itself. The hard part is parsing :)