An organization suspects a stealthy malware infection on a critical server. Traditional antivirus and EDR solutions have not detected anything. Which forensic approach would be most effective in identifying the malware, given that it likely resides only in memory?
Acquiring a memory dump and analyzing it with Volatility is the correct approach because it preserves the volatile state where fileless malware resides, capturing the actual code, injected processes, and hooked kernel structures. Memory forensics allows investigators to enumerate running processes, inspect process memory and VAD trees, and extract indicators that would be lost on reboot, providing the most direct evidence of the infection.
Why this answer
The malware resides only in memory, making it invisible to disk-based scans. Memory forensics with tools like Volatility allows investigators to analyze RAM artifacts (e.g., processes, network connections, injected code) to detect stealthy malware that never writes to disk.
Exam trap
The CHFI exam often tests the misconception that live analysis tools (like Task Manager or Process Explorer) are sufficient for detecting memory-resident malware, but they fail to reveal hidden or injected code that only memory forensics can uncover.
How to eliminate wrong answers
Option A is wrong because a full disk scan with updated antivirus signatures targets files on disk, but the malware is memory-resident and never written to disk, so it will not be detected. Option C is wrong because live analysis using built-in Windows tools like Task Manager provides only a high-level view of processes and cannot reveal hidden or injected code, rootkits, or kernel-level artifacts that require deep memory structure parsing. Option D is wrong because analyzing network traffic with a NetFlow analyzer can show anomalous communication patterns but cannot directly identify malware that resides only in memory; it lacks the ability to inspect process memory, loaded modules, or code injection.