Complete Guide to Endpoint Security & EDR for Modern Infrastructure
Fileless Malware Detection: How to Catch Threats That Leave No Trace
Fileless malware operates entirely in memory using legitimate system tools like PowerShell and WMI, evading traditional file-based detection. Catching fileless threats requires behavioural analysis of process execution chains, memory scanning, script block logging, and monitoring for anomalous use of living-off-the-land binaries (LOLBins).

Andreas Johansson · Chief Executive Officer
Senior IT management leader with 25 years of experience in Cloud, Security, and Datacenter infrastructure.
What Makes Malware "Fileless"
Traditional malware drops executable files to disk — these files can be scanned, signature-matched, and blocked by antivirus. Fileless malware takes a fundamentally different approach: it operates entirely in memory, leveraging legitimate system tools and processes to execute malicious code without ever writing a traditional malware binary to disk.
This approach is devastatingly effective against traditional security tools. File-based scanners have nothing to scan. Signature databases have no file hash to match. The malicious activity uses the same tools that system administrators use daily — PowerShell, WMI, .NET framework, Windows Management Instrumentation — making it extraordinarily difficult to distinguish from legitimate activity.
Common Fileless Attack Techniques
PowerShell-Based Attacks
PowerShell is the most commonly weaponised living-off-the-land tool. Attackers use it to:
- Download and execute payloads directly in memory using
Invoke-ExpressionandDownloadString - Run encoded commands that bypass basic content inspection
- Access .NET framework capabilities for sophisticated in-memory operations
- Establish persistence through scheduled tasks and registry modifications
WMI-Based Persistence
Windows Management Instrumentation provides a powerful persistence mechanism. Attackers create WMI event subscriptions that trigger malicious actions on system events — like every time the system boots or a specific process starts — without any files on disk.
Process Injection
Malicious code is injected into the memory space of legitimate running processes. The injected code executes within the context of a trusted process, inheriting its permissions and evading process-based detection rules.
Registry-Resident Malware
While not strictly "fileless," some malware stores its code in the Windows Registry rather than the file system. Registry values can contain encoded scripts or shellcode that are extracted and executed in memory on each boot.
Detection Strategies
Behavioural Analysis
Since fileless malware uses legitimate tools, detection must focus on how those tools are used, not what files they create:
- PowerShell spawned by Microsoft Office applications (macro-based initial access)
- Encoded PowerShell commands exceeding typical length
- WMI process creation from unusual parent processes
- .NET assembly loading from PowerShell sessions
- Process execution chains that don't match expected patterns
Script Block Logging
PowerShell Script Block Logging records the actual content of every PowerShell script that executes, including decoded versions of encoded commands. This provides visibility into PowerShell activity regardless of obfuscation techniques.
Memory Scanning
EDR agents that scan process memory can detect injected code, reflective DLL loading, and other in-memory indicators of compromise. Memory scanning catches threats that file system scanning misses entirely.
AMSI Integration
The Antimalware Scan Interface (AMSI) provides a standardised interface for security tools to inspect content at the point of execution — including dynamically generated scripts, decoded commands, and in-memory payloads. AMSI catches malicious content that was encrypted or encoded at rest.
Building Fileless Threat Detection
Implement these capabilities in priority order:
- Enable PowerShell logging — Script Block Logging and Module Logging are essential and free
- Deploy EDR with behavioural analysis — Endpoint agents that monitor process behaviour patterns
- Implement process execution monitoring — Track parent-child process relationships
- Configure memory scanning — Periodic and event-triggered memory inspection
- Integrate with threat intelligence — Known fileless TTPs inform detection rules
How SeqOps fits
SeqOps isn't an EDR or antivirus, and it works alongside them. Its lightweight agent on Windows and Linux servers reports installed software and configuration, and SeqOps matches it against known vulnerabilities and benchmarks.