Mandiant, Inc.
Code injection technique for remediation at an endpoint of a network

Last updated:

Abstract:

A technique injects code into a suspicious process containing malware executing on a node to enable remediation at the node. Illustratively, the technique may inject code into the suspicious process during instrumentation of the malware in a micro-virtual machine (VM) to monitor malicious behavior and to enable remediation of that behavior at a node embodied as an endpoint. According to the technique, code may be injected into the suspicious process during instrumentation in the micro-VM of the endpoint to restore states of kernel resources (e.g., memory) that may be infected (i.e., altered) by behavior (actions) of the malware.

Status:
Grant
Type:

Utility

Filling date:

23 Oct 2015

Issue date:

12 Nov 2019