CHFI Storage Forensics and File System Analysis Practice Question
During memory analysis, an examiner uses the Volatility 'malfind' plugin and discovers a process with executable code in an executable heap. Which technique is most likely being used by malware to avoid detection?
⚠ Common exam trap
CHFI often tests the distinction between where code is stored (heap vs. DLL vs. process image) and candidates confuse heap spraying with DLL injection because both involve injecting code, but heap spraying specifically places code in the heap, not in a loaded module.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Heap spraying
The 'malfind' plugin in Volatility detects memory pages with executable code in non-standard locations, such as executable heaps. Heap spraying is a technique where malware allocates multiple heap blocks and fills them with malicious shellcode, then exploits a vulnerability to redirect execution to that heap. This results in executable code present in heap memory, which malfind flags.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Process hollowing
Why it's wrong here
Process hollowing creates a suspended process, replaces its original executable image with malicious code, and then resumes the process. The injected payload is mapped as a private memory region with its own PE headers and is not part of the heap segments that malfind inspects. Malfind's heuristic identifies executable writable regions containing code-like patterns, but process hollowing's code resides in a section-backed mapping or a freshly allocated region rather than in heap allocations, so it would not be the technique directly diagnosed by malfind.
- ✗
DLL injection
Why it's wrong here
DLL injection typically forces a target process to load a DLL by calling LoadLibrary through a remote thread. The DLL is mapped as a MEM_IMAGE region with its own sections and proper file backing, not as a heap allocation. Volatility's malfind plugin specifically scans for private executable heap pages that often contain sprayed shellcode, so a legitimately loaded DLL would not exhibit the same heuristic signature. Instead, DLL injection is more reliably exposed by dlllist, ldrmodules, or the injects plugin.
- ✓
Heap spraying
Why this is correct
Heap spraying is an exploitation technique that fills the process heap with many blocks of crafted data, often a repeated pattern of benign opcodes followed by shellcode, to make execution land at a predictable address. These allocations are typically marked PAGE_EXECUTE_READWRITE, which is exactly what Volatility's malfind plugin targets when it searches for executable writable heap regions. Malfind further validates the region by disassembling the contents, and the repetitive coding pattern found in a heap spray is a strong indicator of this technique, making it the correct answer.
- ✗
Reflective DLL loading
Why it's wrong here
Reflective DLL loading manually maps a DLL from memory into a process without using LoadLibrary, usually by allocating private memory via VirtualAlloc and copying image sections. Although the resulting allocation may be executable and writable—and thus could be flagged by malfind—it contains a complete PE structure rather than the repeated filler pattern characteristic of heap spraying. A reflective DLL is a stealthier image mapping that preserves the shape of a DLL, whereas heap spraying populates the heap with numerous small blocks of code. Therefore, while both are memory-resident, malfind's heap-oriented heuristics point specifically to heap spraying, not reflective DLL loading.
Go deeper
Related to this question
About these practice questions
One of 745 original CHFI practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CHFI practice question is part of Courseiva's free EC-Council certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CHFI exam.