Get a Demo
Under Attack?
Illustration of five surfboards standing upright on a beach with palm trees. Each has a command line icon. The text reads, Detect Suspicious Fileless Process Execution. A logo with the word upwind is at the top. The background is a gradient blue sky.

Detect Suspicious Fileless Process Execution

<br />
<b>Warning</b>:  Undefined variable $photo in <b>/nas/content/live/landing173/wp-content/themes/bricks/includes/elements/code.php(236) : eval()'d code</b> on line <b>24</b><br />
<br />
<b>Warning</b>:  Trying to access array offset on value of type null in <b>/nas/content/live/landing173/wp-content/themes/bricks/includes/elements/code.php(236) : eval()'d code</b> on line <b>24</b><br />
Denise Ashur March 04, 2024

Detect Suspicious Fileless Process Execution

We’re excited to announce the ability to monitor and detect malicious “fileless execution” events. This capability enables alerting when a process is executed without using an executable file on a disk or file system.

Fileless Execution

The action of a process being executed using an in-memory executable file is a common defense evasion technique used by malicious actors to avoid writing an executable or new code to the disk, allowing an attacker to avoid being detected by file system scanning.

In addition, in many cases, security & DevOps teams already deploy their containers’ root filesystem in read-only mode. This theoretically prevents an attacker from downloading their malware executable to disk. However, sophisticated attackers use fileless malware and execute commands directly in memory.

Although this is a common malware technique, there are also some legitimate use cases for fileless execution, such as a just-in-time (JIT) compiler writing compiled code to memory and executing it from memory.

fileless-detection-example-1024x654

Indicators of Compromise

Upwind’s fileless execution detection is intended to find fileless malware, which is a form of attack that does not require the installation of new executables on a system, although attackers will need to access the environment. Common methods of fileless execution attacks include compromising native tools, memory-only malware, fileless ransomware and stolen credentials.

In a fileless execution attack, attackers commonly do the following:

  1. Exploit a vulnerability and gain remote access to an environment
  2. Obtain credentials for the compromised environment, allowing the attacker to traverse into other systems
  3. Modify the registry and establish a backdoor.
  4. Access data and exfiltrate it out to the network.

Upwind leverages runtime data to rapidly identify unusual fileless executions and immediately alert you to suspicious activity. Read more about fileless execution detections in the Upwind Documentation Center.

Contents

Further Reading

upwind-identities

Introducing the Upwind Identity Graph: End-to-End Identity Security

Identity used to be treated as a directory problem: find the user, inspect the groups, review the assigned roles, and decide whether the account has too much access. That model no longer matches the cloud. A single person may authenticate through Okta, inherit permissions from multiple groups, receive role assignments in more than one cloud,…
AI-Graph

Introducing the Upwind AI Graph: Extending AI Inventory Beyond Cloud Infrastructure

As enterprise adoption of artificial intelligence accelerates, modern AI infrastructure has expanded far beyond traditional cloud perimeters. Securing enterprise AI today requires complete visibility across four distinct operational layers: Traditional cloud security tools stop at the cloud provider boundary. When enterprise teams connect directly to external AI Providers, security teams lose sight of access paths,…
ChatGPT Image Aug 4, 2026, 08_46_20 AM

Keyv Supply Chain Compromise: An npm Worm That Takes Its Orders From an Ethereum Smart Contract

Executive Summary On August 4, 2026 at 09:35 UTC, [email protected] was published to npm carrying a credential stealer, an npm worm, and a persistence mechanism designed to detonate during incident response.  Keyv ranks #274 by npm reach and is present in 84,759 customer environments, and the release shipped with valid GitHub OIDC provenance and a…
Add the Upwind RSS Feed to Slack
Connect the Upwind RSS Feed to your Slack.
Follow the how-to here.
Threat RSS
Add the Upwind RSS Feed to Slack
Connect the Upwind RSS Feed to your Slack.
Follow the how-to here.
Main RSS