Mandiant, Inc.
Code injection technique for remediation at an endpoint of a network
Last updated:
Abstract:
A technique injects code into a suspicious process containing malware executing on a node to enable remediation at the node. Illustratively, the technique may inject code into the suspicious process during instrumentation of the malware in a micro-virtual machine (VM) to monitor malicious behavior and to enable remediation of that behavior at a node embodied as an endpoint. According to the technique, code may be injected into the suspicious process during instrumentation in the micro-VM of the endpoint to restore states of kernel resources (e.g., memory) that may be infected (i.e., altered) by behavior (actions) of the malware.
Status:
Grant
Type:
Utility
Filling date:
23 Oct 2015
Issue date:
12 Nov 2019