[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fKe_ZFdavZB4sQn3WndxT1QR1o26B3aicANmaKQwDdoo":3},{"id":4,"question":5,"answer":6,"answerHtml":7,"slug":8,"keywords":9,"article":10,"status":34,"aiModel":39,"aiConfidence":39,"updatedAt":52,"createdAt":53,"_status":51},1207,"How does using virtual disks achieve a fileless approach in penetration testing, and what advantages does it offer?","This technique maps part of the system's memory as a RAM disk using virtual disk software like ImDisk. Instead of writing malicious files to the physical hard drive, all file operations occur in memory. The key advantages are that no traces remain on the hard drive (so file recovery forensics fails) and the entire virtual disk disappears after a system reboot, making it ideal for stealthy, [fileless implementation](\u002Fnews\u002Fpenetration-techniques-fileless-implementation-using-virtual-disks).","\u003Cp>This technique maps part of the system&#39;s memory as a RAM disk using virtual disk software like ImDisk. Instead of writing malicious files to the physical hard drive, all file operations occur in memory. The key advantages are that no traces remain on the hard drive (so file recovery forensics fails) and the entire virtual disk disappears after a system reboot, making it ideal for stealthy, [fileless implementation](\u002Fnews\u002Fpenetration-techniques-fileless-implementation-using-virtual-disks).\u003C\u002Fp>\u003Cp>\u003Ca href=\"\u002Fnews\u002Fpenetration-techniques-fileless-implementation-using-virtual-disks\">Read the related One Day Sec article\u003C\u002Fa>\u003C\u002Fp>","how-does-using-virtual-disks-achieve-a-fileless-approach-in-penetration-testing--1777480132074","fileless, virtual disk, RAM disk, ImDisk, penetration testing, forensics, stealth",{"id":11,"title":12,"slug":13,"description":14,"content":15,"contentHtml":30,"cover":31,"author":32,"views":19,"readingTime":33,"status":34,"publishedAt":35,"seo":36,"tags":41,"qaPairs":42,"meta":48,"updatedAt":49,"createdAt":50,"_status":51},293,"Penetration Techniques - 'Fileless' Implementation Using Virtual Disks","penetration-techniques-fileless-implementation-using-virtual-disks","Explore fileless penetration techniques using virtual disks for RAM-based execution, avoiding hard drive writes. Learn implementation, forensic analysis, and detection methods.",{"root":16},{"type":17,"format":18,"indent":19,"version":20,"children":21,"direction":29},"root","",0,1,[22],{"type":23,"format":18,"indent":19,"version":20,"children":24,"direction":29},"paragraph",[25],{"mode":26,"text":27,"type":28,"style":18,"detail":19,"format":19,"version":20},"normal","\u003Chtml>\u003Chead>\u003C\u002Fhead>\u003Cbody>\u003Ch2>0x00 Preface\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>In penetration testing, fileless techniques such as code injection, memory execution, registry manipulation, PowerShell, or WMI are often used to increase the difficulty of detection and analysis.\u003C\u002Fp>\u003Cp>From a penetration perspective, under certain conditions, achieving a completely 'fileless' process may not be possible, requiring files to be written to the hard disk, which can easily be forensically examined and analyzed.\u003C\u002Fp>\u003Cp>Recently, I came across an article introducing a method using virtual disks, which precisely addresses this issue.\u003C\u002Fp>\u003Cp>From a defensive standpoint, how can such methods be detected and intercepted?\u003C\u002Fp>\u003Cp>Reference article address:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fdiablohorn.com\u002F2018\u002F08\u002F06\u002Fcreating-a-ram-disk-through-meterpreter\u002F\u003C\u002Fp>\u003Cp>This article will test it, introduce implementation details, resolve unresolved issues from the original text, combine exploitation ideas, and analyze detection and interception methods.\u003C\u002Fp>\u003Ch2>0x01 Introduction\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>This article will cover the following:\u003C\u002Fp>\u003Cul>\u003Cli>Implementation Principles\u003C\u002Fli>\u003Cli>Method Reproduction\u003C\u002Fli>\u003Cli>Remove residual hard drive icons\u003C\u002Fli>\u003Cli>Support for folder operations\u003C\u002Fli>\u003Cli>Forensic analysis\u003C\u002Fli>\u003Cli>Detection and interception\u003C\u002Fli>\u003C\u002Ful>\u003Ch2>0x02 Implementation Principle\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>In Windows systems, deleting a file on a hard drive only modifies the file's MFT. If the file content has not been overwritten, the file can be recovered.\u003C\u002Fp>\u003Cp>For detailed information on deletion and recovery, refer to the previous article 'Penetration Techniques—File Recovery and Deletion in Windows Systems'.\u003C\u002Fp>\u003Cp>If a virtual disk is used to map memory locally and create a RAM disk, its usage is no different from a real hard drive, and it offers the following two advantages:\u003C\u002Fp>\u003Col>\u003Cli>No write operations are performed on the hard drive, eliminating the possibility of hard drive file recovery.\u003C\u002Fli>\u003Cli>Files in the RAM disk are automatically deleted after a system reboot.\u003C\u002Fli>\u003C\u002Fol>\u003Ch2>0x03 Method Reproduction\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>Reproduce the implementation method described in the article at:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fdiablohorn.com\u002F2018\u002F08\u002F06\u002Fcreating-a-ram-disk-through-meterpreter\u002F\u003C\u002Fp>\u003Ch3>ImDisk\u003C\u002Fh3>\u003Cp>Open-source tool capable of creating virtual disks, introduction and download address:\u003C\u002Fp>\u003Cp>http:\u002F\u002Fwww.ltr-data.se\u002Fopencode.html\u002F\u003C\u002Fp>\u003Cp>A prompt dialog will appear during installation, as shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770016707272_0_f45c32ba19.jpeg\">\u003C\u002Fp>\u003Cp>After successful installation, the driver file imdisk.sys is released under C:\\Windows\\System32\\drivers\\, and the startup program imdisk.exe along with its support files are released under C:\\Windows\\System32\\\u003C\u002Fp>\u003Cp>After successful installation, enter imdisk in the command line to start ImDisk, and the command description will be echoed\u003C\u002Fp>\u003Ch3>Secondary utilization\u003C\u002Fh3>\u003Cp>Author DiabloHorn leverages the open-source tool ImDisk for secondary utilization, enabling command-line installation, loading, and creation\u002Fdeletion of virtual disks\u003C\u002Fp>\u003Cp>Preparation work:\u003C\u002Fp>\u003Ch4>1. Write code to implement driver installation, loading, and creation\u002Fdeletion of virtual disks\u003C\u002Fh4>\u003Cp>Code address:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fgithub.com\u002FDiabloHorn\u002Fcliramdisk\u003C\u002Fp>\u003Cp>My test compilation environment is VS2015. Save the contents included in the header file stdafx.h in the project to cliramdisk.cpp, compile directly to pass, and generate the file cliramdisk.exe\u003C\u002Fp>\u003Ch4>2. Install ImDisk on the test system to obtain the driver file imdisk.sys\u003C\u002Fh4>\u003Cp>After installation, copy the driver file imdisk.sys to the location `C:\\Windows\\System32\\drivers\\`\u003C\u002Fp>\u003Cp>It is worth noting that the driver file imdisk.sys contains a digital signature\u003C\u002Fp>\u003Ch4>3. Write a registry file to add driver file information\u003C\u002Fh4>\u003Cp>The content is as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>Windows Registry Editor Version 5.00\u003Cbr>\u003Cbr>[HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\ImDisk]\u003Cbr>\"DisplayName\"=\"ImDisk Virtual Disk Driver\"\u003Cbr>\"Description\"=\"Disk emulation driver\"\u003Cbr>\"Type\"=dword:00000001\u003Cbr>\"Start\"=dword:00000004\u003Cbr>\"ErrorControl\"=dword:00000000\u003Cbr>\"ImagePath\"=hex(2):5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,00,\\\u003Cbr>  74,00,5c,00,73,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,44,00,52,\\\u003Cbr>  00,49,00,56,00,45,00,52,00,53,00,5c,00,69,00,6d,00,64,00,69,00,73,00,6b,00,\\\u003Cbr>  2e,00,73,00,79,00,73,00,00,00\u003Cbr>\"DeleteFlag\"=dword:00000001\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Save as imdiskdriver.reg\u003C\u002Fp>\u003Ch3>Actual testing\u003C\u002Fh3>\u003Cp>1. Import registry, add driver file information\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>reg import imdiskdriver.reg\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>2. Upload driver file\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>copy imdisk.sys C:\\Windows\\System32\\drivers\\\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>3. Load driver file\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>cliramdisk.exe i\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>4. Create virtual disk (size 200MB)\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>cliramdisk.exe c 209715200 R: 0\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>5. Format as NTFS\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>format R: \u002FFS:NTFS \u002FQ \u002Fy\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Afterwards, files can be uploaded to drive R, and they will be automatically deleted after system reboot\u003C\u002Fp>\u003Cp>6. View virtual disk\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>cliramdisk.exe l\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>7. Delete virtual disk\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>cliramdisk.exe d 0\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Incomplete deletion, disk icon still displayed\u003C\u002Fp>\u003Cp>As shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770016715235_1_7798a7c226.jpeg\">\u003C\u002Fp>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>This bug does not exist when using ImDisk to delete virtual disks\u003C\u002Fp>\u003Ch3>Shortcomings\u003C\u002Fh3>\u003Col>\u003Cli>Incomplete deletion, disk icon still displayed\u003C\u002Fli>\u003Cli>Does not support creating virtual disks for folders\u003C\u002Fli>\u003C\u002Fol>\u003Ch2>0x04 Optimization\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>To address the two shortcomings mentioned in the previous section, consider using ImDisk directly, but command-line installation and usage of ImDisk need to be implemented\u003C\u002Fp>\u003Cp>This presents one solution\u003C\u002Fp>\u003Ch3>Preparation Work\u003C\u002Fh3>\u003Cp>1. Install ImDisk on the test system to obtain support files\u003C\u002Fp>\u003Cul>\u003Cli>C:\\Windows\\System32\\drivers\\imdisk.sys\u003C\u002Fli>\u003Cli>C:\\Windows\\System32\\imdisk.exe\u003C\u002Fli>\u003Cli>C:\\Windows\\System32\\imdisk.cpl\u003C\u002Fli>\u003C\u002Ful>\u003Cp>2. Write code to implement driver installation\u003C\u002Fp>\u003Cp>Code repository:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fgithub.com\u002FDiabloHorn\u002Fcliramdisk\u003C\u002Fp>\u003Cp>The driver loading functionality in the code can be used directly here\u003C\u002Fp>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>All files required for testing have been uploaded to GitHub. Download link:\u003C\u002Fp>\u003Cp>An open-source project\u003C\u002Fp>\u003Ch3>Actual Testing\u003C\u002Fh3>\u003Cp>1. Add registry entries to include driver file information\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>reg add hklm\\SYSTEM\\CurrentControlSet\\Services\\ImDisk \u002Fv DisplayName \u002Ft REG_SZ \u002Fd \"ImDisk Virtual Disk Driver\"\u003Cbr>reg add hklm\\SYSTEM\\CurrentControlSet\\Services\\ImDisk \u002Fv Description \u002Ft REG_SZ \u002Fd \"Disk emulation driver\"\u003Cbr>reg add hklm\\SYSTEM\\CurrentControlSet\\Services\\ImDisk \u002Fv Type \u002Ft REG_DWORD \u002Fd 1\u003Cbr>reg add hklm\\SYSTEM\\CurrentControlSet\\Services\\ImDisk \u002Fv Start \u002Ft REG_DWORD \u002Fd 4\u003Cbr>reg add hklm\\SYSTEM\\CurrentControlSet\\Services\\ImDisk \u002Fv ErrorControl \u002Ft REG_DWORD \u002Fd 0\u003Cbr>reg add hklm\\SYSTEM\\CurrentControlSet\\Services\\ImDisk \u002Fv ImagePath \u002Ft REG_EXPAND_SZ \u002Fd \"\\SystemRoot\\system32\\DRIVERS\\imdisk.sys\"\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>2. Upload driver file\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>copy imdisk.sys C:\\Windows\\System32\\drivers\\\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>3. Load driver file\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>cliramdisk.exe i\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>4. Create virtual disk Z: with size 10MB, automatically format as NTFS\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>imdisk -a -s 10M -m Z: -p \"\u002FFS:NTFS \u002FY \u002FQ\"\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>5. Delete virtual disk Z:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>imdisk -d -m Z:\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>No bug of hard disk icon remaining\u003C\u002Fp>\u003Cp>6. Folder Operations\u003C\u002Fp>\u003Cp>(1) Creation\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>md C:\\Windows\\Temp\\test\u003Cbr>imdisk -a -s 10M -m C:\\Windows\\Temp\\test -p \"\u002FFS:NTFS \u002FY \u002FQ\"\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Requires an empty folder, otherwise creation will fail\u003C\u002Fp>\u003Cp>(2) Deletion\u003C\u002Fp>\u003Cp>Unmount virtual disk:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>imdisk -d -m C:\\Windows\\Temp\\test\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Or directly delete the folder:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>rd C:\\Windows\\Temp\\test\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>7. Uninstall Driver File\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>cliramdisk.exe u\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch2>0x05 Forensic Analysis\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>1. Create a virtual disk for the folder\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>md C:\\Windows\\Temp\\test\u003Cbr>imdisk -a -s 10M -m C:\\Windows\\Temp\\test -p \"\u002FFS:NTFS \u002FY \u002FQ\"\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>2. Write test file\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>echo AAAAAAAAAAAAAAAAA&gt;C:\\Windows\\Temp\\test\\1.txt\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>3. Use WinHex to view file content\u003C\u002Fp>\u003Cp>Download link:\u003C\u002Fp>\u003Cp>http:\u002F\u002Fwww.x-ways.net\u002Fwinhex\u002F\u003C\u002Fp>\u003Cp>Select Tools -&gt; Open Disk, choose drive letter c:\u003C\u002Fp>\u003Cp>Locate the folder C:\\Windows\\Temp\\test\u003C\u002Fp>\u003Cp>Unable to find test file 1.txt\u003C\u002Fp>\u003Cp>Proving the file was not written to the hard disk\u003C\u002Fp>\u003Ch2>0x06 Detection and Interception\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>Cannot retrieve attacker-uploaded files by recovering hard disk files\u003C\u002Fp>\u003Cp>Considering the exploitation approach, monitoring driver files and intercepting the loading of the driver file imdisk.sys can be considered\u003C\u002Fp>\u003Ch2>0x07 Summary\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>This article tested the method of using virtual hard disks to achieve 'fileless' execution, addressing two issues (incomplete deletion and lack of folder support). The conclusion is verified: files in virtual hard disks cannot be retrieved by restoring hard disk files.\u003C\u002Fp>\u003Cp>Finally, combining the exploitation approach, methods for detection and interception are analyzed.\u003C\u002Fp>\u003C\u002Fbody>\u003C\u002Fhtml>","text","ltr","\u003Chtml>\u003Chead>\u003C\u002Fhead>\u003Cbody>\u003Ch2>0x00 Preface\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>In penetration testing, fileless techniques such as code injection, memory execution, registry manipulation, PowerShell, or WMI are often used to increase the difficulty of detection and analysis.\u003C\u002Fp>\u003Cp>From a penetration perspective, under certain conditions, achieving a completely 'fileless' process may not be possible, requiring files to be written to the hard disk, which can easily be forensically examined and analyzed.\u003C\u002Fp>\u003Cp>Recently, I came across an article introducing a method using virtual disks, which precisely addresses this issue.\u003C\u002Fp>\u003Cp>From a defensive standpoint, how can such methods be detected and intercepted?\u003C\u002Fp>\u003Cp>Reference article address:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fdiablohorn.com\u002F2018\u002F08\u002F06\u002Fcreating-a-ram-disk-through-meterpreter\u002F\u003C\u002Fp>\u003Cp>This article will test it, introduce implementation details, resolve unresolved issues from the original text, combine exploitation ideas, and analyze detection and interception methods.\u003C\u002Fp>\u003Ch2>0x01 Introduction\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>This article will cover the following:\u003C\u002Fp>\u003Cul>\u003Cli>Implementation Principles\u003C\u002Fli>\u003Cli>Method Reproduction\u003C\u002Fli>\u003Cli>Remove residual hard drive icons\u003C\u002Fli>\u003Cli>Support for folder operations\u003C\u002Fli>\u003Cli>Forensic analysis\u003C\u002Fli>\u003Cli>Detection and interception\u003C\u002Fli>\u003C\u002Ful>\u003Ch2>0x02 Implementation Principle\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>In Windows systems, deleting a file on a hard drive only modifies the file's MFT. If the file content has not been overwritten, the file can be recovered.\u003C\u002Fp>\u003Cp>For detailed information on deletion and recovery, refer to the previous article 'Penetration Techniques—File Recovery and Deletion in Windows Systems'.\u003C\u002Fp>\u003Cp>If a virtual disk is used to map memory locally and create a RAM disk, its usage is no different from a real hard drive, and it offers the following two advantages:\u003C\u002Fp>\u003Col>\u003Cli>No write operations are performed on the hard drive, eliminating the possibility of hard drive file recovery.\u003C\u002Fli>\u003Cli>Files in the RAM disk are automatically deleted after a system reboot.\u003C\u002Fli>\u003C\u002Fol>\u003Ch2>0x03 Method Reproduction\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>Reproduce the implementation method described in the article at:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fdiablohorn.com\u002F2018\u002F08\u002F06\u002Fcreating-a-ram-disk-through-meterpreter\u002F\u003C\u002Fp>\u003Ch3>ImDisk\u003C\u002Fh3>\u003Cp>Open-source tool capable of creating virtual disks, introduction and download address:\u003C\u002Fp>\u003Cp>http:\u002F\u002Fwww.ltr-data.se\u002Fopencode.html\u002F\u003C\u002Fp>\u003Cp>A prompt dialog will appear during installation, as shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770016707272_0_f45c32ba19-1.jpeg\">\u003C\u002Fp>\u003Cp>After successful installation, the driver file imdisk.sys is released under C:\\Windows\\System32\\drivers\\, and the startup program imdisk.exe along with its support files are released under C:\\Windows\\System32\\\u003C\u002Fp>\u003Cp>After successful installation, enter imdisk in the command line to start ImDisk, and the command description will be echoed\u003C\u002Fp>\u003Ch3>Secondary utilization\u003C\u002Fh3>\u003Cp>Author DiabloHorn leverages the open-source tool ImDisk for secondary utilization, enabling command-line installation, loading, and creation\u002Fdeletion of virtual disks\u003C\u002Fp>\u003Cp>Preparation work:\u003C\u002Fp>\u003Ch4>1. Write code to implement driver installation, loading, and creation\u002Fdeletion of virtual disks\u003C\u002Fh4>\u003Cp>Code address:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fgithub.com\u002FDiabloHorn\u002Fcliramdisk\u003C\u002Fp>\u003Cp>My test compilation environment is VS2015. Save the contents included in the header file stdafx.h in the project to cliramdisk.cpp, compile directly to pass, and generate the file cliramdisk.exe\u003C\u002Fp>\u003Ch4>2. Install ImDisk on the test system to obtain the driver file imdisk.sys\u003C\u002Fh4>\u003Cp>After installation, copy the driver file imdisk.sys to the location `C:\\Windows\\System32\\drivers\\`\u003C\u002Fp>\u003Cp>It is worth noting that the driver file imdisk.sys contains a digital signature\u003C\u002Fp>\u003Ch4>3. Write a registry file to add driver file information\u003C\u002Fh4>\u003Cp>The content is as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>Windows Registry Editor Version 5.00\u003Cbr>\u003Cbr>[HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\ImDisk]\u003Cbr>\"DisplayName\"=\"ImDisk Virtual Disk Driver\"\u003Cbr>\"Description\"=\"Disk emulation driver\"\u003Cbr>\"Type\"=dword:00000001\u003Cbr>\"Start\"=dword:00000004\u003Cbr>\"ErrorControl\"=dword:00000000\u003Cbr>\"ImagePath\"=hex(2):5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,00,\\\u003Cbr>  74,00,5c,00,73,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,44,00,52,\\\u003Cbr>  00,49,00,56,00,45,00,52,00,53,00,5c,00,69,00,6d,00,64,00,69,00,73,00,6b,00,\\\u003Cbr>  2e,00,73,00,79,00,73,00,00,00\u003Cbr>\"DeleteFlag\"=dword:00000001\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Save as imdiskdriver.reg\u003C\u002Fp>\u003Ch3>Actual testing\u003C\u002Fh3>\u003Cp>1. Import registry, add driver file information\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>reg import imdiskdriver.reg\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>2. Upload driver file\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>copy imdisk.sys C:\\Windows\\System32\\drivers\\\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>3. Load driver file\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>cliramdisk.exe i\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>4. Create virtual disk (size 200MB)\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>cliramdisk.exe c 209715200 R: 0\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>5. Format as NTFS\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>format R: \u002FFS:NTFS \u002FQ \u002Fy\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Afterwards, files can be uploaded to drive R, and they will be automatically deleted after system reboot\u003C\u002Fp>\u003Cp>6. View virtual disk\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>cliramdisk.exe l\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>7. Delete virtual disk\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>cliramdisk.exe d 0\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Incomplete deletion, disk icon still displayed\u003C\u002Fp>\u003Cp>As shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770016715235_1_7798a7c226-1.jpeg\">\u003C\u002Fp>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>This bug does not exist when using ImDisk to delete virtual disks\u003C\u002Fp>\u003Ch3>Shortcomings\u003C\u002Fh3>\u003Col>\u003Cli>Incomplete deletion, disk icon still displayed\u003C\u002Fli>\u003Cli>Does not support creating virtual disks for folders\u003C\u002Fli>\u003C\u002Fol>\u003Ch2>0x04 Optimization\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>To address the two shortcomings mentioned in the previous section, consider using ImDisk directly, but command-line installation and usage of ImDisk need to be implemented\u003C\u002Fp>\u003Cp>This presents one solution\u003C\u002Fp>\u003Ch3>Preparation Work\u003C\u002Fh3>\u003Cp>1. Install ImDisk on the test system to obtain support files\u003C\u002Fp>\u003Cul>\u003Cli>C:\\Windows\\System32\\drivers\\imdisk.sys\u003C\u002Fli>\u003Cli>C:\\Windows\\System32\\imdisk.exe\u003C\u002Fli>\u003Cli>C:\\Windows\\System32\\imdisk.cpl\u003C\u002Fli>\u003C\u002Ful>\u003Cp>2. Write code to implement driver installation\u003C\u002Fp>\u003Cp>Code repository:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fgithub.com\u002FDiabloHorn\u002Fcliramdisk\u003C\u002Fp>\u003Cp>The driver loading functionality in the code can be used directly here\u003C\u002Fp>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>All files required for testing have been uploaded to GitHub. Download link:\u003C\u002Fp>\u003Cp>An open-source project\u003C\u002Fp>\u003Ch3>Actual Testing\u003C\u002Fh3>\u003Cp>1. Add registry entries to include driver file information\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>reg add hklm\\SYSTEM\\CurrentControlSet\\Services\\ImDisk \u002Fv DisplayName \u002Ft REG_SZ \u002Fd \"ImDisk Virtual Disk Driver\"\u003Cbr>reg add hklm\\SYSTEM\\CurrentControlSet\\Services\\ImDisk \u002Fv Description \u002Ft REG_SZ \u002Fd \"Disk emulation driver\"\u003Cbr>reg add hklm\\SYSTEM\\CurrentControlSet\\Services\\ImDisk \u002Fv Type \u002Ft REG_DWORD \u002Fd 1\u003Cbr>reg add hklm\\SYSTEM\\CurrentControlSet\\Services\\ImDisk \u002Fv Start \u002Ft REG_DWORD \u002Fd 4\u003Cbr>reg add hklm\\SYSTEM\\CurrentControlSet\\Services\\ImDisk \u002Fv ErrorControl \u002Ft REG_DWORD \u002Fd 0\u003Cbr>reg add hklm\\SYSTEM\\CurrentControlSet\\Services\\ImDisk \u002Fv ImagePath \u002Ft REG_EXPAND_SZ \u002Fd \"\\SystemRoot\\system32\\DRIVERS\\imdisk.sys\"\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>2. Upload driver file\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>copy imdisk.sys C:\\Windows\\System32\\drivers\\\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>3. Load driver file\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>cliramdisk.exe i\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>4. Create virtual disk Z: with size 10MB, automatically format as NTFS\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>imdisk -a -s 10M -m Z: -p \"\u002FFS:NTFS \u002FY \u002FQ\"\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>5. Delete virtual disk Z:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>imdisk -d -m Z:\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>No bug of hard disk icon remaining\u003C\u002Fp>\u003Cp>6. Folder Operations\u003C\u002Fp>\u003Cp>(1) Creation\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>md C:\\Windows\\Temp\\test\u003Cbr>imdisk -a -s 10M -m C:\\Windows\\Temp\\test -p \"\u002FFS:NTFS \u002FY \u002FQ\"\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Requires an empty folder, otherwise creation will fail\u003C\u002Fp>\u003Cp>(2) Deletion\u003C\u002Fp>\u003Cp>Unmount virtual disk:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>imdisk -d -m C:\\Windows\\Temp\\test\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Or directly delete the folder:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>rd C:\\Windows\\Temp\\test\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>7. Uninstall Driver File\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>cliramdisk.exe u\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch2>0x05 Forensic Analysis\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>1. Create a virtual disk for the folder\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>md C:\\Windows\\Temp\\test\u003Cbr>imdisk -a -s 10M -m C:\\Windows\\Temp\\test -p \"\u002FFS:NTFS \u002FY \u002FQ\"\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>2. Write test file\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>echo AAAAAAAAAAAAAAAAA&gt;C:\\Windows\\Temp\\test\\1.txt\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>3. Use WinHex to view file content\u003C\u002Fp>\u003Cp>Download link:\u003C\u002Fp>\u003Cp>http:\u002F\u002Fwww.x-ways.net\u002Fwinhex\u002F\u003C\u002Fp>\u003Cp>Select Tools -&gt; Open Disk, choose drive letter c:\u003C\u002Fp>\u003Cp>Locate the folder C:\\Windows\\Temp\\test\u003C\u002Fp>\u003Cp>Unable to find test file 1.txt\u003C\u002Fp>\u003Cp>Proving the file was not written to the hard disk\u003C\u002Fp>\u003Ch2>0x06 Detection and Interception\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>Cannot retrieve attacker-uploaded files by recovering hard disk files\u003C\u002Fp>\u003Cp>Considering the exploitation approach, monitoring driver files and intercepting the loading of the driver file imdisk.sys can be considered\u003C\u002Fp>\u003Ch2>0x07 Summary\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>This article tested the method of using virtual hard disks to achieve 'fileless' execution, addressing two issues (incomplete deletion and lack of folder support). The conclusion is verified: files in virtual hard disks cannot be retrieved by restoring hard disk files.\u003C\u002Fp>\u003Cp>Finally, combining the exploitation approach, methods for detection and interception are analyzed.\u003C\u002Fp>\u003C\u002Fbody>\u003C\u002Fhtml>",7,"Onedaysec",5,"published","2026-02-02T07:25:19.684Z",{"title":37,"description":14,"keywords":38,"ogImage":39,"canonicalUrl":39,"noIndex":40},"Fileless Penetration Techniques Using Virtual Disks: Detection & Implementation","fileless attack, virtual disk, RAM disk, penetration testing, ImDisk, forensic analysis, detection methods, memory execution, cybersecurity",null,false,[],{"docs":43,"hasNextPage":40},[44,45,46,47,4],1211,1210,1209,1208,{"title":39,"description":39,"image":39},"2026-07-24T15:37:08.850Z","2026-07-23T16:02:40.397Z","draft","2026-07-23T16:17:24.660Z","2026-07-23T16:17:24.659Z"]