Skip main navigation

Hooked process

Article detailing user mod and kernel mode hooking techniques.
© PA Knowledge Ltd | 7Safe Training

Process hooking

Malware must run!

All malware must be loaded into memory to function as either a process in its own right or it must form part of another process using a technique known as hooking.

A process running in its own right should be easy to find right? Well this is a yes and no answer! A standalone suspect process should be easier to find for an experienced malware investigator, but this is not necessarily the case for the lay person. Any suspect process may well seem legitimate without further investigation.

A hooked process (a process using another process to function) will require some specialist knowledge and understanding of Windows memory structures or the inner workings of the Windows operating system to identify. Complex malware will always hide within other processes to avoid detection.

Top Tip: Most malware will initially run from a user account area. Any process executing from a user area should be deemed suspect unless it can be verified as a legitimate process.

Additional information…

There are actually 3 user and 5 kernel hooking techniques. These are:

Graphic depicting the names of user mode and kernel mode hooking techniques. User mode: DLL. IAT & Inline. Kernel: mode SSDT, IRP, IDT, GDT & Sysenter

© PA Knowledge Ltd | 7Safe Training
This article is from the free online

Introduction to Digital Forensics: Malware Analysis and Investigations

Created by
FutureLearn - Learning For Life

Our purpose is to transform access to education.

We offer a diverse selection of courses from leading universities and cultural institutions from around the world. These are delivered one step at a time, and are accessible on mobile, tablet and desktop, so you can fit learning around your life.

We believe learning should be an enjoyable, social experience, so our courses offer the opportunity to discuss what you’re learning with others as you go, helping you make fresh discoveries and form new ideas.
You can unlock new opportunities with unlimited access to hundreds of online short courses for a year by subscribing to our Unlimited package. Build your knowledge with top universities and organisations.

Learn more about how FutureLearn is transforming access to education