[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fnVA7TT3OaYYRYPe3HN4oy40RSGyJdqNmdna4KfEprDQ":3},{"id":4,"question":5,"answer":6,"answerHtml":7,"slug":8,"keywords":9,"article":10,"status":34,"aiModel":39,"aiConfidence":39,"updatedAt":52,"createdAt":52,"_status":51},1211,"Why is the virtual disk technique considered superior to traditional fileless methods like code injection or PowerShell, and what trade-offs does it have?","Traditional fileless methods avoid writing to disk entirely but often require complex exploits or leave in-memory artifacts detectable by EDR. Virtual disks offer a middle ground: they mimic real disk operations (so commodity malware can be used) but all data vanishes on reboot. The trade-off is the need to deliver the ImDisk driver and support files, which can be flagged by driver-load monitoring. However, once loaded, the attacker gains a fully functional, persistent-in-session file system without hard drive traces, a technique that complements other [backdoor implementations using VMware Tools](\u002Fnews\u002Fpenetration-basics-backdoor-implementation-using-vmware-tools).","\u003Cp>Traditional fileless methods avoid writing to disk entirely but often require complex exploits or leave in-memory artifacts detectable by EDR. Virtual disks offer a middle ground: they mimic real disk operations (so commodity malware can be used) but all data vanishes on reboot. The trade-off is the need to deliver the ImDisk driver and support files, which can be flagged by driver-load monitoring. However, once loaded, the attacker gains a fully functional, persistent-in-session file system without hard drive traces, a technique that complements other [backdoor implementations using VMware Tools](\u002Fnews\u002Fpenetration-basics-backdoor-implementation-using-vmware-tools).\u003C\u002Fp>\u003Cp>\u003Ca href=\"\u002Fnews\u002Fpenetration-techniques-fileless-implementation-using-virtual-disks\">Read the related One Day Sec article\u003C\u002Fa>\u003C\u002Fp>","why-is-the-virtual-disk-technique-considered-superior-to-traditional-fileless-me-1777480132414","fileless, virtual disk, ImDisk, driver, trade-offs, penetration testing",{"id":11,"title":12,"slug":13,"description":14,"content":15,"contentHtml":30,"cover":31,"author":32,"views":19,"readingTime":33,"status":34,"publishedAt":35,"seo":36,"tags":41,"qaPairs":42,"meta":48,"updatedAt":49,"createdAt":50,"_status":51},293,"Penetration Techniques - 'Fileless' Implementation Using Virtual Disks","penetration-techniques-fileless-implementation-using-virtual-disks","Explore fileless penetration techniques using virtual disks for RAM-based execution, avoiding hard drive writes. Learn implementation, forensic analysis, and detection methods.",{"root":16},{"type":17,"format":18,"indent":19,"version":20,"children":21,"direction":29},"root","",0,1,[22],{"type":23,"format":18,"indent":19,"version":20,"children":24,"direction":29},"paragraph",[25],{"mode":26,"text":27,"type":28,"style":18,"detail":19,"format":19,"version":20},"normal","\u003Chtml>\u003Chead>\u003C\u002Fhead>\u003Cbody>\u003Ch2>0x00 Preface\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>In penetration testing, fileless techniques such as code injection, memory execution, registry manipulation, PowerShell, or WMI are often used to increase the difficulty of detection and analysis.\u003C\u002Fp>\u003Cp>From a penetration perspective, under certain conditions, achieving a completely 'fileless' process may not be possible, requiring files to be written to the hard disk, which can easily be forensically examined and analyzed.\u003C\u002Fp>\u003Cp>Recently, I came across an article introducing a method using virtual disks, which precisely addresses this issue.\u003C\u002Fp>\u003Cp>From a defensive standpoint, how can such methods be detected and intercepted?\u003C\u002Fp>\u003Cp>Reference article address:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fdiablohorn.com\u002F2018\u002F08\u002F06\u002Fcreating-a-ram-disk-through-meterpreter\u002F\u003C\u002Fp>\u003Cp>This article will test it, introduce implementation details, resolve unresolved issues from the original text, combine exploitation ideas, and analyze detection and interception methods.\u003C\u002Fp>\u003Ch2>0x01 Introduction\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>This article will cover the following:\u003C\u002Fp>\u003Cul>\u003Cli>Implementation Principles\u003C\u002Fli>\u003Cli>Method Reproduction\u003C\u002Fli>\u003Cli>Remove residual hard drive icons\u003C\u002Fli>\u003Cli>Support for folder operations\u003C\u002Fli>\u003Cli>Forensic analysis\u003C\u002Fli>\u003Cli>Detection and interception\u003C\u002Fli>\u003C\u002Ful>\u003Ch2>0x02 Implementation Principle\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>In Windows systems, deleting a file on a hard drive only modifies the file's MFT. If the file content has not been overwritten, the file can be recovered.\u003C\u002Fp>\u003Cp>For detailed information on deletion and recovery, refer to the previous article 'Penetration Techniques—File Recovery and Deletion in Windows Systems'.\u003C\u002Fp>\u003Cp>If a virtual disk is used to map memory locally and create a RAM disk, its usage is no different from a real hard drive, and it offers the following two advantages:\u003C\u002Fp>\u003Col>\u003Cli>No write operations are performed on the hard drive, eliminating the possibility of hard drive file recovery.\u003C\u002Fli>\u003Cli>Files in the RAM disk are automatically deleted after a system reboot.\u003C\u002Fli>\u003C\u002Fol>\u003Ch2>0x03 Method Reproduction\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>Reproduce the implementation method described in the article at:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fdiablohorn.com\u002F2018\u002F08\u002F06\u002Fcreating-a-ram-disk-through-meterpreter\u002F\u003C\u002Fp>\u003Ch3>ImDisk\u003C\u002Fh3>\u003Cp>Open-source tool capable of creating virtual disks, introduction and download address:\u003C\u002Fp>\u003Cp>http:\u002F\u002Fwww.ltr-data.se\u002Fopencode.html\u002F\u003C\u002Fp>\u003Cp>A prompt dialog will appear during installation, as shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770016707272_0_f45c32ba19.jpeg\">\u003C\u002Fp>\u003Cp>After successful installation, the driver file imdisk.sys is released under C:\\Windows\\System32\\drivers\\, and the startup program imdisk.exe along with its support files are released under C:\\Windows\\System32\\\u003C\u002Fp>\u003Cp>After successful installation, enter imdisk in the command line to start ImDisk, and the command description will be echoed\u003C\u002Fp>\u003Ch3>Secondary utilization\u003C\u002Fh3>\u003Cp>Author DiabloHorn leverages the open-source tool ImDisk for secondary utilization, enabling command-line installation, loading, and creation\u002Fdeletion of virtual disks\u003C\u002Fp>\u003Cp>Preparation work:\u003C\u002Fp>\u003Ch4>1. Write code to implement driver installation, loading, and creation\u002Fdeletion of virtual disks\u003C\u002Fh4>\u003Cp>Code address:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fgithub.com\u002FDiabloHorn\u002Fcliramdisk\u003C\u002Fp>\u003Cp>My test compilation environment is VS2015. Save the contents included in the header file stdafx.h in the project to cliramdisk.cpp, compile directly to pass, and generate the file cliramdisk.exe\u003C\u002Fp>\u003Ch4>2. Install ImDisk on the test system to obtain the driver file imdisk.sys\u003C\u002Fh4>\u003Cp>After installation, copy the driver file imdisk.sys to the location `C:\\Windows\\System32\\drivers\\`\u003C\u002Fp>\u003Cp>It is worth noting that the driver file imdisk.sys contains a digital signature\u003C\u002Fp>\u003Ch4>3. Write a registry file to add driver file information\u003C\u002Fh4>\u003Cp>The content is as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>Windows Registry Editor Version 5.00\u003Cbr>\u003Cbr>[HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\ImDisk]\u003Cbr>\"DisplayName\"=\"ImDisk Virtual Disk Driver\"\u003Cbr>\"Description\"=\"Disk emulation driver\"\u003Cbr>\"Type\"=dword:00000001\u003Cbr>\"Start\"=dword:00000004\u003Cbr>\"ErrorControl\"=dword:00000000\u003Cbr>\"ImagePath\"=hex(2):5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,00,\\\u003Cbr>  74,00,5c,00,73,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,44,00,52,\\\u003Cbr>  00,49,00,56,00,45,00,52,00,53,00,5c,00,69,00,6d,00,64,00,69,00,73,00,6b,00,\\\u003Cbr>  2e,00,73,00,79,00,73,00,00,00\u003Cbr>\"DeleteFlag\"=dword:00000001\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Save as imdiskdriver.reg\u003C\u002Fp>\u003Ch3>Actual testing\u003C\u002Fh3>\u003Cp>1. Import registry, add driver file information\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>reg import imdiskdriver.reg\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>2. Upload driver file\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>copy imdisk.sys C:\\Windows\\System32\\drivers\\\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>3. Load driver file\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>cliramdisk.exe i\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>4. Create virtual disk (size 200MB)\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>cliramdisk.exe c 209715200 R: 0\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>5. Format as NTFS\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>format R: \u002FFS:NTFS \u002FQ \u002Fy\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Afterwards, files can be uploaded to drive R, and they will be automatically deleted after system reboot\u003C\u002Fp>\u003Cp>6. View virtual disk\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>cliramdisk.exe l\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>7. Delete virtual disk\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>cliramdisk.exe d 0\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Incomplete deletion, disk icon still displayed\u003C\u002Fp>\u003Cp>As shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770016715235_1_7798a7c226.jpeg\">\u003C\u002Fp>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>This bug does not exist when using ImDisk to delete virtual disks\u003C\u002Fp>\u003Ch3>Shortcomings\u003C\u002Fh3>\u003Col>\u003Cli>Incomplete deletion, disk icon still displayed\u003C\u002Fli>\u003Cli>Does not support creating virtual disks for folders\u003C\u002Fli>\u003C\u002Fol>\u003Ch2>0x04 Optimization\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>To address the two shortcomings mentioned in the previous section, consider using ImDisk directly, but command-line installation and usage of ImDisk need to be implemented\u003C\u002Fp>\u003Cp>This presents one solution\u003C\u002Fp>\u003Ch3>Preparation Work\u003C\u002Fh3>\u003Cp>1. Install ImDisk on the test system to obtain support files\u003C\u002Fp>\u003Cul>\u003Cli>C:\\Windows\\System32\\drivers\\imdisk.sys\u003C\u002Fli>\u003Cli>C:\\Windows\\System32\\imdisk.exe\u003C\u002Fli>\u003Cli>C:\\Windows\\System32\\imdisk.cpl\u003C\u002Fli>\u003C\u002Ful>\u003Cp>2. Write code to implement driver installation\u003C\u002Fp>\u003Cp>Code repository:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fgithub.com\u002FDiabloHorn\u002Fcliramdisk\u003C\u002Fp>\u003Cp>The driver loading functionality in the code can be used directly here\u003C\u002Fp>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>All files required for testing have been uploaded to GitHub. Download link:\u003C\u002Fp>\u003Cp>An open-source project\u003C\u002Fp>\u003Ch3>Actual Testing\u003C\u002Fh3>\u003Cp>1. Add registry entries to include driver file information\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>reg add hklm\\SYSTEM\\CurrentControlSet\\Services\\ImDisk \u002Fv DisplayName \u002Ft REG_SZ \u002Fd \"ImDisk Virtual Disk Driver\"\u003Cbr>reg add hklm\\SYSTEM\\CurrentControlSet\\Services\\ImDisk \u002Fv Description \u002Ft REG_SZ \u002Fd \"Disk emulation driver\"\u003Cbr>reg add hklm\\SYSTEM\\CurrentControlSet\\Services\\ImDisk \u002Fv Type \u002Ft REG_DWORD \u002Fd 1\u003Cbr>reg add hklm\\SYSTEM\\CurrentControlSet\\Services\\ImDisk \u002Fv Start \u002Ft REG_DWORD \u002Fd 4\u003Cbr>reg add hklm\\SYSTEM\\CurrentControlSet\\Services\\ImDisk \u002Fv ErrorControl \u002Ft REG_DWORD \u002Fd 0\u003Cbr>reg add hklm\\SYSTEM\\CurrentControlSet\\Services\\ImDisk \u002Fv ImagePath \u002Ft REG_EXPAND_SZ \u002Fd \"\\SystemRoot\\system32\\DRIVERS\\imdisk.sys\"\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>2. Upload driver file\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>copy imdisk.sys C:\\Windows\\System32\\drivers\\\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>3. Load driver file\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>cliramdisk.exe i\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>4. Create virtual disk Z: with size 10MB, automatically format as NTFS\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>imdisk -a -s 10M -m Z: -p \"\u002FFS:NTFS \u002FY \u002FQ\"\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>5. Delete virtual disk Z:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>imdisk -d -m Z:\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>No bug of hard disk icon remaining\u003C\u002Fp>\u003Cp>6. Folder Operations\u003C\u002Fp>\u003Cp>(1) Creation\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>md C:\\Windows\\Temp\\test\u003Cbr>imdisk -a -s 10M -m C:\\Windows\\Temp\\test -p \"\u002FFS:NTFS \u002FY \u002FQ\"\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Requires an empty folder, otherwise creation will fail\u003C\u002Fp>\u003Cp>(2) Deletion\u003C\u002Fp>\u003Cp>Unmount virtual disk:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>imdisk -d -m C:\\Windows\\Temp\\test\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Or directly delete the folder:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>rd C:\\Windows\\Temp\\test\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>7. Uninstall Driver File\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>cliramdisk.exe u\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch2>0x05 Forensic Analysis\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>1. Create a virtual disk for the folder\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>md C:\\Windows\\Temp\\test\u003Cbr>imdisk -a -s 10M -m C:\\Windows\\Temp\\test -p \"\u002FFS:NTFS \u002FY \u002FQ\"\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>2. Write test file\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>echo AAAAAAAAAAAAAAAAA&gt;C:\\Windows\\Temp\\test\\1.txt\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>3. Use WinHex to view file content\u003C\u002Fp>\u003Cp>Download link:\u003C\u002Fp>\u003Cp>http:\u002F\u002Fwww.x-ways.net\u002Fwinhex\u002F\u003C\u002Fp>\u003Cp>Select Tools -&gt; Open Disk, choose drive letter c:\u003C\u002Fp>\u003Cp>Locate the folder C:\\Windows\\Temp\\test\u003C\u002Fp>\u003Cp>Unable to find test file 1.txt\u003C\u002Fp>\u003Cp>Proving the file was not written to the hard disk\u003C\u002Fp>\u003Ch2>0x06 Detection and Interception\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>Cannot retrieve attacker-uploaded files by recovering hard disk files\u003C\u002Fp>\u003Cp>Considering the exploitation approach, monitoring driver files and intercepting the loading of the driver file imdisk.sys can be considered\u003C\u002Fp>\u003Ch2>0x07 Summary\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>This article tested the method of using virtual hard disks to achieve 'fileless' execution, addressing two issues (incomplete deletion and lack of folder support). The conclusion is verified: files in virtual hard disks cannot be retrieved by restoring hard disk files.\u003C\u002Fp>\u003Cp>Finally, combining the exploitation approach, methods for detection and interception are analyzed.\u003C\u002Fp>\u003C\u002Fbody>\u003C\u002Fhtml>","text","ltr","\u003Chtml>\u003Chead>\u003C\u002Fhead>\u003Cbody>\u003Ch2>0x00 Preface\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>In penetration testing, fileless techniques such as code injection, memory execution, registry manipulation, PowerShell, or WMI are often used to increase the difficulty of detection and analysis.\u003C\u002Fp>\u003Cp>From a penetration perspective, under certain conditions, achieving a completely 'fileless' process may not be possible, requiring files to be written to the hard disk, which can easily be forensically examined and analyzed.\u003C\u002Fp>\u003Cp>Recently, I came across an article introducing a method using virtual disks, which precisely addresses this issue.\u003C\u002Fp>\u003Cp>From a defensive standpoint, how can such methods be detected and intercepted?\u003C\u002Fp>\u003Cp>Reference article address:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fdiablohorn.com\u002F2018\u002F08\u002F06\u002Fcreating-a-ram-disk-through-meterpreter\u002F\u003C\u002Fp>\u003Cp>This article will test it, introduce implementation details, resolve unresolved issues from the original text, combine exploitation ideas, and analyze detection and interception methods.\u003C\u002Fp>\u003Ch2>0x01 Introduction\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>This article will cover the following:\u003C\u002Fp>\u003Cul>\u003Cli>Implementation Principles\u003C\u002Fli>\u003Cli>Method Reproduction\u003C\u002Fli>\u003Cli>Remove residual hard drive icons\u003C\u002Fli>\u003Cli>Support for folder operations\u003C\u002Fli>\u003Cli>Forensic analysis\u003C\u002Fli>\u003Cli>Detection and interception\u003C\u002Fli>\u003C\u002Ful>\u003Ch2>0x02 Implementation Principle\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>In Windows systems, deleting a file on a hard drive only modifies the file's MFT. If the file content has not been overwritten, the file can be recovered.\u003C\u002Fp>\u003Cp>For detailed information on deletion and recovery, refer to the previous article 'Penetration Techniques—File Recovery and Deletion in Windows Systems'.\u003C\u002Fp>\u003Cp>If a virtual disk is used to map memory locally and create a RAM disk, its usage is no different from a real hard drive, and it offers the following two advantages:\u003C\u002Fp>\u003Col>\u003Cli>No write operations are performed on the hard drive, eliminating the possibility of hard drive file recovery.\u003C\u002Fli>\u003Cli>Files in the RAM disk are automatically deleted after a system reboot.\u003C\u002Fli>\u003C\u002Fol>\u003Ch2>0x03 Method Reproduction\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>Reproduce the implementation method described in the article at:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fdiablohorn.com\u002F2018\u002F08\u002F06\u002Fcreating-a-ram-disk-through-meterpreter\u002F\u003C\u002Fp>\u003Ch3>ImDisk\u003C\u002Fh3>\u003Cp>Open-source tool capable of creating virtual disks, introduction and download address:\u003C\u002Fp>\u003Cp>http:\u002F\u002Fwww.ltr-data.se\u002Fopencode.html\u002F\u003C\u002Fp>\u003Cp>A prompt dialog will appear during installation, as shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770016707272_0_f45c32ba19-1.jpeg\">\u003C\u002Fp>\u003Cp>After successful installation, the driver file imdisk.sys is released under C:\\Windows\\System32\\drivers\\, and the startup program imdisk.exe along with its support files are released under C:\\Windows\\System32\\\u003C\u002Fp>\u003Cp>After successful installation, enter imdisk in the command line to start ImDisk, and the command description will be echoed\u003C\u002Fp>\u003Ch3>Secondary utilization\u003C\u002Fh3>\u003Cp>Author DiabloHorn leverages the open-source tool ImDisk for secondary utilization, enabling command-line installation, loading, and creation\u002Fdeletion of virtual disks\u003C\u002Fp>\u003Cp>Preparation work:\u003C\u002Fp>\u003Ch4>1. Write code to implement driver installation, loading, and creation\u002Fdeletion of virtual disks\u003C\u002Fh4>\u003Cp>Code address:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fgithub.com\u002FDiabloHorn\u002Fcliramdisk\u003C\u002Fp>\u003Cp>My test compilation environment is VS2015. Save the contents included in the header file stdafx.h in the project to cliramdisk.cpp, compile directly to pass, and generate the file cliramdisk.exe\u003C\u002Fp>\u003Ch4>2. Install ImDisk on the test system to obtain the driver file imdisk.sys\u003C\u002Fh4>\u003Cp>After installation, copy the driver file imdisk.sys to the location `C:\\Windows\\System32\\drivers\\`\u003C\u002Fp>\u003Cp>It is worth noting that the driver file imdisk.sys contains a digital signature\u003C\u002Fp>\u003Ch4>3. Write a registry file to add driver file information\u003C\u002Fh4>\u003Cp>The content is as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>Windows Registry Editor Version 5.00\u003Cbr>\u003Cbr>[HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\ImDisk]\u003Cbr>\"DisplayName\"=\"ImDisk Virtual Disk Driver\"\u003Cbr>\"Description\"=\"Disk emulation driver\"\u003Cbr>\"Type\"=dword:00000001\u003Cbr>\"Start\"=dword:00000004\u003Cbr>\"ErrorControl\"=dword:00000000\u003Cbr>\"ImagePath\"=hex(2):5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,00,\\\u003Cbr>  74,00,5c,00,73,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,44,00,52,\\\u003Cbr>  00,49,00,56,00,45,00,52,00,53,00,5c,00,69,00,6d,00,64,00,69,00,73,00,6b,00,\\\u003Cbr>  2e,00,73,00,79,00,73,00,00,00\u003Cbr>\"DeleteFlag\"=dword:00000001\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Save as imdiskdriver.reg\u003C\u002Fp>\u003Ch3>Actual testing\u003C\u002Fh3>\u003Cp>1. Import registry, add driver file information\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>reg import imdiskdriver.reg\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>2. Upload driver file\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>copy imdisk.sys C:\\Windows\\System32\\drivers\\\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>3. Load driver file\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>cliramdisk.exe i\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>4. Create virtual disk (size 200MB)\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>cliramdisk.exe c 209715200 R: 0\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>5. Format as NTFS\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>format R: \u002FFS:NTFS \u002FQ \u002Fy\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Afterwards, files can be uploaded to drive R, and they will be automatically deleted after system reboot\u003C\u002Fp>\u003Cp>6. View virtual disk\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>cliramdisk.exe l\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>7. Delete virtual disk\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>cliramdisk.exe d 0\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Incomplete deletion, disk icon still displayed\u003C\u002Fp>\u003Cp>As shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770016715235_1_7798a7c226-1.jpeg\">\u003C\u002Fp>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>This bug does not exist when using ImDisk to delete virtual disks\u003C\u002Fp>\u003Ch3>Shortcomings\u003C\u002Fh3>\u003Col>\u003Cli>Incomplete deletion, disk icon still displayed\u003C\u002Fli>\u003Cli>Does not support creating virtual disks for folders\u003C\u002Fli>\u003C\u002Fol>\u003Ch2>0x04 Optimization\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>To address the two shortcomings mentioned in the previous section, consider using ImDisk directly, but command-line installation and usage of ImDisk need to be implemented\u003C\u002Fp>\u003Cp>This presents one solution\u003C\u002Fp>\u003Ch3>Preparation Work\u003C\u002Fh3>\u003Cp>1. Install ImDisk on the test system to obtain support files\u003C\u002Fp>\u003Cul>\u003Cli>C:\\Windows\\System32\\drivers\\imdisk.sys\u003C\u002Fli>\u003Cli>C:\\Windows\\System32\\imdisk.exe\u003C\u002Fli>\u003Cli>C:\\Windows\\System32\\imdisk.cpl\u003C\u002Fli>\u003C\u002Ful>\u003Cp>2. Write code to implement driver installation\u003C\u002Fp>\u003Cp>Code repository:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fgithub.com\u002FDiabloHorn\u002Fcliramdisk\u003C\u002Fp>\u003Cp>The driver loading functionality in the code can be used directly here\u003C\u002Fp>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>All files required for testing have been uploaded to GitHub. Download link:\u003C\u002Fp>\u003Cp>An open-source project\u003C\u002Fp>\u003Ch3>Actual Testing\u003C\u002Fh3>\u003Cp>1. Add registry entries to include driver file information\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>reg add hklm\\SYSTEM\\CurrentControlSet\\Services\\ImDisk \u002Fv DisplayName \u002Ft REG_SZ \u002Fd \"ImDisk Virtual Disk Driver\"\u003Cbr>reg add hklm\\SYSTEM\\CurrentControlSet\\Services\\ImDisk \u002Fv Description \u002Ft REG_SZ \u002Fd \"Disk emulation driver\"\u003Cbr>reg add hklm\\SYSTEM\\CurrentControlSet\\Services\\ImDisk \u002Fv Type \u002Ft REG_DWORD \u002Fd 1\u003Cbr>reg add hklm\\SYSTEM\\CurrentControlSet\\Services\\ImDisk \u002Fv Start \u002Ft REG_DWORD \u002Fd 4\u003Cbr>reg add hklm\\SYSTEM\\CurrentControlSet\\Services\\ImDisk \u002Fv ErrorControl \u002Ft REG_DWORD \u002Fd 0\u003Cbr>reg add hklm\\SYSTEM\\CurrentControlSet\\Services\\ImDisk \u002Fv ImagePath \u002Ft REG_EXPAND_SZ \u002Fd \"\\SystemRoot\\system32\\DRIVERS\\imdisk.sys\"\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>2. Upload driver file\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>copy imdisk.sys C:\\Windows\\System32\\drivers\\\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>3. Load driver file\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>cliramdisk.exe i\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>4. Create virtual disk Z: with size 10MB, automatically format as NTFS\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>imdisk -a -s 10M -m Z: -p \"\u002FFS:NTFS \u002FY \u002FQ\"\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>5. Delete virtual disk Z:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>imdisk -d -m Z:\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>No bug of hard disk icon remaining\u003C\u002Fp>\u003Cp>6. Folder Operations\u003C\u002Fp>\u003Cp>(1) Creation\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>md C:\\Windows\\Temp\\test\u003Cbr>imdisk -a -s 10M -m C:\\Windows\\Temp\\test -p \"\u002FFS:NTFS \u002FY \u002FQ\"\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Requires an empty folder, otherwise creation will fail\u003C\u002Fp>\u003Cp>(2) Deletion\u003C\u002Fp>\u003Cp>Unmount virtual disk:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>imdisk -d -m C:\\Windows\\Temp\\test\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Or directly delete the folder:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>rd C:\\Windows\\Temp\\test\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>7. Uninstall Driver File\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>cliramdisk.exe u\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch2>0x05 Forensic Analysis\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>1. Create a virtual disk for the folder\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>md C:\\Windows\\Temp\\test\u003Cbr>imdisk -a -s 10M -m C:\\Windows\\Temp\\test -p \"\u002FFS:NTFS \u002FY \u002FQ\"\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>2. Write test file\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>echo AAAAAAAAAAAAAAAAA&gt;C:\\Windows\\Temp\\test\\1.txt\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>3. Use WinHex to view file content\u003C\u002Fp>\u003Cp>Download link:\u003C\u002Fp>\u003Cp>http:\u002F\u002Fwww.x-ways.net\u002Fwinhex\u002F\u003C\u002Fp>\u003Cp>Select Tools -&gt; Open Disk, choose drive letter c:\u003C\u002Fp>\u003Cp>Locate the folder C:\\Windows\\Temp\\test\u003C\u002Fp>\u003Cp>Unable to find test file 1.txt\u003C\u002Fp>\u003Cp>Proving the file was not written to the hard disk\u003C\u002Fp>\u003Ch2>0x06 Detection and Interception\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>Cannot retrieve attacker-uploaded files by recovering hard disk files\u003C\u002Fp>\u003Cp>Considering the exploitation approach, monitoring driver files and intercepting the loading of the driver file imdisk.sys can be considered\u003C\u002Fp>\u003Ch2>0x07 Summary\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>This article tested the method of using virtual hard disks to achieve 'fileless' execution, addressing two issues (incomplete deletion and lack of folder support). The conclusion is verified: files in virtual hard disks cannot be retrieved by restoring hard disk files.\u003C\u002Fp>\u003Cp>Finally, combining the exploitation approach, methods for detection and interception are analyzed.\u003C\u002Fp>\u003C\u002Fbody>\u003C\u002Fhtml>",7,"Onedaysec",5,"published","2026-02-02T07:25:19.684Z",{"title":37,"description":14,"keywords":38,"ogImage":39,"canonicalUrl":39,"noIndex":40},"Fileless Penetration Techniques Using Virtual Disks: Detection & Implementation","fileless attack, virtual disk, RAM disk, penetration testing, ImDisk, forensic analysis, detection methods, memory execution, cybersecurity",null,false,[],{"docs":43,"hasNextPage":40},[4,44,45,46,47],1210,1209,1208,1207,{"title":39,"description":39,"image":39},"2026-07-24T15:37:08.850Z","2026-07-23T16:02:40.397Z","draft","2026-07-23T16:17:26.047Z"]