Windows Internals, Memory Forensics, EDR, and Network Detection Engineering
Introduction: The Memory-Only Battlefield
- Why “Fileless” Is a Misleading Term
- What This Book Teaches You to Do
- Defensive Ethics, Safe Research, and Controlled Simulation
- The Reference Laboratory Architecture
- How to Use This Book
Chapter 1: Windows Internals for Detection Engineers
- User Mode, Kernel Mode, and Detection Visibility
- Processes, Threads, and Execution Contexts
- Virtual Memory, Address Spaces, and Paging
- Heaps, Stacks, and Data Layout
- PEB, TEB, and Process Metadata
- Handles, Objects, Tokens, and Access Rights
- Integrity Levels, Sessions, and Services
- The Registry and Configuration State
- System Calls and API Layers: A Defensive View
- Chapter Summary
Chapter 2: PE/COFF Structures and Executable Image Behavior
- PE File Format: Headers, Sections, and Metadata
- Imports, Exports, Relocations, and TLS Callbacks
- The Windows Loader: How Images Become Processes
- Dynamic Linking and DLL Search Paths
- Signed Versus Unsigned Modules and Authenticode
- Memory-Mapped Images and Their Normal Appearance
- Side-Loading Indicators and Module Provenance Anomalies
- Chapter Summary
Chapter 3: Managed Execution, Scripting, and Automation Surfaces
- The CLR, Managed Code, and Runtime Observability
- PowerShell Execution: Policies, Logging, and Telemetry
- Scripting Hosts: cscript, wscript, and Suspicious Invocation
- WMI Architecture, Event Subscriptions, and Abuse Indicators
- COM Objects, Activation Patterns, and Detection Signals
- RPC, Named Pipes, and Inter-Process Communication Artifacts
- Chapter Summary
Chapter 4: Windows Telemetry Infrastructure
- Event Tracing for Windows (ETW): Providers, Sessions, and Events
- The Windows Event Log: Channels, Sources, and Reliability
- PowerShell Script Block Logging and Module Logging
- AMSI: Architecture, Integration Points, and Limitations
- Microsoft Defender Antivirus Telemetry and Interfaces
- Sysmon-Style Extended Telemetry and Custom Providers
- Telemetry Gaps, Performance Costs, and Baseline Behavior
- Chapter Summary
Chapter 5: The Memory-Resident Threat Spectrum
- A Working Taxonomy: From Scripted Attacks to Pure Memory Implants
- Living-off-the-Land: Abuse of Legitimate Binaries
- Suspicious Process Creation and Parent-Child Relationships
- Anomalous Command Interpreters and Script Execution
- Unexpected Module Loading and DLL Search Path Manipulation
- In-Memory PE Artifacts and Reflective Loading Indicators
- Process Injection Patterns: What Defenders Can Observe
- Hollowing-Like Anomalies and Image Replacement Signals
- Module Stomping, Token Misuse, and Persistence Telemetry
- Chapter Summary
Chapter 6: Memory Forensics on Windows
- Memory Acquisition Principles and Evidence Integrity
- Virtual Versus Physical Addresses: What Matters to Defenders
- Process Enumeration and Hidden/Anomalous Process Detection
- Loaded Modules, Unlinked DLLs, and Image Analysis
- VAD Trees and Memory Map Inspection
- Executable Memory Regions and Permission Anomalies
- Thread Stacks, Handles, and Inter-Process Artifacts
- Strings, Configuration Data, and Embedded Artifacts
- Network Artifacts in Memory and Connection State
- YARA Scanning, IOC Hunting, and Behavioral Patterns
- Timeline Reconstruction and Process Tree Recovery
- Chapter Summary
Chapter 7: EDR Engineering and Detection Architecture
- Endpoint Telemetry Architecture: Sensors and Data Paths
- Kernel Versus User-Mode Visibility and Trade-offs
- Event Normalization, Enrichment, and Entity Resolution
- Process Ancestry Graphs and Stateful Correlation
- Behavioral Analytics: From IOCs to Attack Patterns
- Rule Engines, Sigma/YARA Concepts, and Detection Logic
- Alert Scoring, Deduplication, Suppression, and Baselining
- Telemetry Integrity, Tamper Awareness, and Sensor Health
- Performance Overhead, Privacy, and Retention Policies
- Chapter Summary
Chapter 8: Network Detection for Memory-Resident Threats
- Windows Networking Fundamentals for Detection
- Socket-to-Process Correlation and Connection Telemetry
- DNS Patterns: DGA, Tunneling, and Beacon Indicators
- HTTP/HTTPS Metadata: Headers, Hostnames, and Timing
- TLS Visible Artifacts: SNI, JA3, and Certificate Signals
- SMB, RDP, and Enterprise Protocol Anomalies
- Beacon Detection: Periodicity, Jitter, and Statistical Methods
- Zeek and Suricata Telemetry for Memory-Resident Threats
- Endpoint-Network Correlation Strategies
- Chapter Summary
Chapter 9: Building a Defensive Research Laboratory
- Virtualization Choices and Isolation Requirements
- Network Segmentation and Controlled Connectivity
- Test Endpoints: Windows Versions, Configurations, and Telemetry
- Forensic Workstations and Analysis Tools
- Packet Capture Infrastructure and Storage
- Synthetic Attack Telemetry and Benign Emulation Frameworks
- Time Synchronization, Logging, and Evidence Management
- Snapshots, Reset Procedures, and Containment Safeguards
- Chapter Summary
Chapter 10: Detection Engineering Methodology
- Threat-Informed Detection and Hypothesis Formulation
- Observable Selection and Telemetry Requirements
- Behavioral Abstractions and ATT&CK Mapping
- Detection-as-Code: Versioning, Review, and Reproducibility
- Unit Testing, Integration Testing, and Replay Validation
- Synthetic Telemetry Generation for Rule Testing
- Precision, Recall, False Positive Budgeting, and Alert Fatigue
- Severity Scoring, Confidence Levels, and Triage Guidance
- Coverage Measurement and Detection Gap Analysis
- Chapter Summary
Chapter 11: Reference Implementation — A Mini EDR Lab
- Repository Structure and Build Environment
- Telemetry Collector: ETW Consumer and Log Normalizer
- PE Parser and Section Analyzer Utility
- Memory Map Inspector for Authorized Processes
- Event Correlation Engine and Stateful Tracking
- Rule Engine with Sigma-Style Pattern Matching
- IOC Scanner and YARA Integration Layer
- Investigation Console and Evidence Export
- Chapter Summary
Chapter 12: Forensic Case Studies and Investigative Workflows
- Case Study 1: Suspicious PowerShell Activity and Outbound Beaconing
- Case Study 2: Anomalous DLL Loading and In-Memory PE Artifacts
- Case Study 3: Unexpected Executable Memory and Process Injection Signals
- Case Study 4: Correlated Endpoint and Network Indicators of Persistence
- From Alert to Conclusion: A Repeatable Investigation Workflow
- Chapter Summary
Chapter 13: Operations, Production Deployment, and Defense Architecture Integration
- Deploying Detection Infrastructure into Production
- Security Hardening Recommendations
- Incident Response Procedures for Memory-Resident Threats
- Coverage Validation Methodology
- Architectural Limitations and Adversarial Trade-offs
- Future Directions for Memory-Resident Threat Defense
- Chapter Summary