Get a Demo
Under Attack?
Illustration of five surfboards standing upright on a beach with palm trees. Each has a command line icon. The text reads, Detect Suspicious Fileless Process Execution. A logo with the word upwind is at the top. The background is a gradient blue sky.

Detect Suspicious Fileless Process Execution

<br />
<b>Warning</b>:  Undefined variable $photo in <b>/nas/content/live/landing173/wp-content/themes/bricks/includes/elements/code.php(236) : eval()'d code</b> on line <b>24</b><br />
<br />
<b>Warning</b>:  Trying to access array offset on value of type null in <b>/nas/content/live/landing173/wp-content/themes/bricks/includes/elements/code.php(236) : eval()'d code</b> on line <b>24</b><br />
Denise Ashur March 04, 2024

Detect Suspicious Fileless Process Execution

We’re excited to announce the ability to monitor and detect malicious “fileless execution” events. This capability enables alerting when a process is executed without using an executable file on a disk or file system.

Fileless Execution

The action of a process being executed using an in-memory executable file is a common defense evasion technique used by malicious actors to avoid writing an executable or new code to the disk, allowing an attacker to avoid being detected by file system scanning.

In addition, in many cases, security & DevOps teams already deploy their containers’ root filesystem in read-only mode. This theoretically prevents an attacker from downloading their malware executable to disk. However, sophisticated attackers use fileless malware and execute commands directly in memory.

Although this is a common malware technique, there are also some legitimate use cases for fileless execution, such as a just-in-time (JIT) compiler writing compiled code to memory and executing it from memory.

fileless-detection-example-1024x654

Indicators of Compromise

Upwind’s fileless execution detection is intended to find fileless malware, which is a form of attack that does not require the installation of new executables on a system, although attackers will need to access the environment. Common methods of fileless execution attacks include compromising native tools, memory-only malware, fileless ransomware and stolen credentials.

In a fileless execution attack, attackers commonly do the following:

  1. Exploit a vulnerability and gain remote access to an environment
  2. Obtain credentials for the compromised environment, allowing the attacker to traverse into other systems
  3. Modify the registry and establish a backdoor.
  4. Access data and exfiltrate it out to the network.

Upwind leverages runtime data to rapidly identify unusual fileless executions and immediately alert you to suspicious activity. Read more about fileless execution detections in the Upwind Documentation Center.

Contents

Further Reading

bucket malware scanning

Upwind Launches Malware Scanning for Cloud Storage Across AWS, Azure, and GCP

Cloud object storage plays a central role in modern applications. Buckets are used to store application assets, exchange files, manage backups, build data pipelines, and share information across services and teams. That flexibility also makes object storage an attractive attack vector. A malicious file uploaded to a bucket can introduce risk into downstream applications, workloads,…
API-ASM Blog

Validate the Real-World Exposure of Your APIs with Upwind Attack Surface Management

Your APIs are probably the least-monitored component of your attack surface. They multiply faster than any team can document, and most scanners only ever pick up the ones you already know about. But that gap just got smaller. Upwind’s Attack Surface Management capabilities now provide a unified view of cloud and API exposure, helping security…
gemini-svg

Metabase Instances Actively Exploited: Unauthenticated Admin Takeover via BI Layer Reset Password SQL Injection (CVE-2026-72898)

Executive Summary Upwind recently observed multiple Advanced Persistent Threat (APT) groups actively exploiting CVE-2026-72898. This vulnerability - an unauthenticated SQL injection in the Metabase password reset endpoint carrying a critical CVSS score of 10.0, was actively exploited as a zero-day before a patch became available. An unauthenticated remote attacker can craft a malicious SQL injection…
Add the Upwind RSS Feed to Slack
Connect the Upwind RSS Feed to your Slack.
Follow the how-to here.
Threat RSS
Add the Upwind RSS Feed to Slack
Connect the Upwind RSS Feed to your Slack.
Follow the how-to here.
Main RSS