{"id":40698,"date":"2020-07-08T18:20:00","date_gmt":"2020-07-08T18:20:00","guid":{"rendered":"https:\/\/icrowdnewswire.com\/?p=2640875"},"modified":"2020-07-08T18:20:00","modified_gmt":"2020-07-08T18:20:00","slug":"fret-not-linux-fans-microsofts-project-freta-is-here-to-peer-deep-into-your-memory-to-spot-malware","status":"publish","type":"post","link":"http:\/\/ipsnews.net\/business\/2020\/07\/08\/fret-not-linux-fans-microsofts-project-freta-is-here-to-peer-deep-into-your-memory-to-spot-malware\/","title":{"rendered":"Fret not, Linux fans, Microsoft\u2019s Project Freta is here to peer deep into your memory\u2026 to spot malware"},"content":{"rendered":"<p><img loading=\"lazy\" decoding=\"async\" width=\"233\" height=\"24\" src=\"https:\/\/icrowdnewswire.com\/wp-content\/uploads\/2020\/06\/3998-ICN.png\" class=\"webfeedsFeaturedVisual wp-post-image\" alt=\"\" style=\"display: block; margin-bottom: 5px; clear:both;max-width: 100%;\" link_thumbnail=\"\" \/><\/p>\n<div id=\"top-col-story\">\n<h2>Shining a Rust-based forensic light into the darker corners of images<\/h2>\n<\/div>\n<div id=\"main-col\">\n<div id=\"article-wrapper\">\n<div id=\"article\">\n<div id=\"body\">\n<p>Boffins in Microsoft Research has pulled the covers off&nbsp;<a href=\"https:\/\/www.microsoft.com\/en-us\/research\/blog\/toward-trusted-sensing-for-the-cloud-introducing-project-freta\/\" target=\"_blank\" rel=\"nofollow noopener noreferrer\">Project Freta<\/a>, a free service aimed at spotting memory malfeasance.<\/p>\n<p>A technology demonstration named for the&nbsp;<a href=\"https:\/\/www.scrapbookpages.com\/Poland\/Warsaw\/Warsaw03.html\" target=\"_blank\" rel=\"nofollow noopener noreferrer\">street in Warsaw, Poland where Marie Curie was born<\/a>, Freta comes from the NExT Security Ventures (NSV) team and is all about taking a VM snapshot and scanning the volatile memory for signs of nefarious behaviour.<\/p>\n<h3 class=\"crosshead\">Smile, you&#8217;ve been snapped<\/h3>\n<p>By working on a captured image and not interacting with the OS, Microsoft reckons the project has a better chance of identifying malware before the offending code can cover its tracks (and potentially destroy data.) The snapshot approach also means there is no need for agents and their like when hunting kernel rootkits and other malicious software.<\/p>\n<p>The project kicked off two years ago, partially in response to existing malware sensors being evaded as malicious code gained the ability to spot when it was being observed and self-destruct to prevent discovery.<\/p>\n<p>Taking a different path to the sensor-malware arms race, the Project Freta requirements called for an offline analysis system that could work in batch mode and a sensor to provide memory captures without executing a clarifying instruction on the guest.<\/p>\n<p>4,000 Linux kernels are now supported (Windows is on the roadmap) and Freta will accept four types of memory images: Hyper-V Memory Snapshot (.vmrs files), LiME image (.lime files), Elf Core Dump of Physical Memory (.core files) and Raw Physical Memory Dump (.raw files.)<\/p>\n<p>&#8220;Currently,&#8221; explained Mike Walker, senior director at New Security Ventures, &#8220;only a Hyper-V checkpoint has been evaluated to provide a reasonable approximation of the &#8216;element of surprise&#8217; necessary to achieve trusted sensing.&#8221;<\/p>\n<p>Once a snapshot is uploaded to the portal (or via an API for automation fans), Freta&nbsp;<a href=\"https:\/\/docs.microsoft.com\/en-gb\/security\/research\/project-freta\/report\/\" target=\"_blank\" rel=\"nofollow noopener noreferrer\">will spit out a report<\/a>&nbsp;breaking down the artefacts present when the volatile memory was imaged. Information such as the kernel modules, interrupt table and in-memory files are all present for inspection.<\/p>\n<p>Very much a tool for investigators, Project Freta will also have a crack at inferring the presence of malware and note potential rootkits, but &#8220;it does not flag everything&#8221; according to Microsoft. The gang also recommends comparing images over time to check for malware that only operates at specific times or in response to certain events.<\/p>\n<p>A sensor has also been developed for Azure that will shunt the volatile memory of live VMs to offline analysis without disrupting execution, but only Microsoft&#8217;s own researchers currently have access to it. For Project Freta, the plan is to add Windows support and fiddle with AI decision making for spotting novel threats.<\/p>\n<p>Project Freta is currently a free service. While the service itself is not fully open source, Microsoft has shovelled a&nbsp;<a href=\"https:\/\/github.com\/Microsoft\/project-freta\" target=\"_blank\" rel=\"nofollow noopener noreferrer\">client-side SDK into GitHub<\/a>, replete with a Python-based command line interface.<\/p>\n<p>While the source behind Project Freta is not yet public, some bits of the code referenced can be found. An engineer on the project&nbsp;<a href=\"https:\/\/www.reddit.com\/r\/rust\/comments\/hmjsvs\/microsoft_researchs_project_freta_given_the\/fx66w4v\" target=\"_blank\" rel=\"nofollow noopener noreferrer\">directed<\/a>&nbsp;those interested to Microsoft&#8217;s&nbsp;<a href=\"https:\/\/github.com\/microsoft\/avml\" target=\"_blank\" rel=\"nofollow noopener noreferrer\">AVML (Acquire Volatile Memory for Linux)<\/a>&nbsp;in GitHub. AVML is an x86_64 userland volatile memory acquisition tool, which can acquire memory without being aware of the target OS distribution. Sound a bit familiar? Like Project Freta, it is written in Rust.<\/p>\n<\/div>\n<\/div>\n<\/div>\n<\/div>\n<p class=\"tags\">\n<div><strong>See Campaign: <\/strong><a href=\"https:\/\/www.scrapbookpages.com\/Poland\/Warsaw\/Warsaw03.html\" target=\"_blank\">https:\/\/www.scrapbookpages.com\/Poland\/Warsaw\/Warsaw03.html<\/a><br \/><b>Contact Information:<\/b><br \/>Amiee<\/p>\n<p><b>Tags:<\/b><br \/><a href=\"\"><\/a>, <a href=\"https:\/\/icrowdnewswire.com\/category\/news-category\/wire\/\" rel=\"category tag\">Wire<\/a>, <a href=\"https:\/\/icrowdnewswire.com\/category\/global-regions\/united-states\/\" rel=\"category tag\">United States<\/a>, <a href=\"https:\/\/icrowdnewswire.com\/category\/language\/english\/\" rel=\"category tag\">English<\/a><\/p>\n<p><img loading=\"lazy\" decoding=\"async\" src=\"\" alt=\"image\" width=\"400\" height=\"300\" class=\"cwdfimg\" \/><\/div>\n<div>\n<h3>Contact Information:<\/h3>\n<p>Amiee<\/p>\n<\/p><\/div>\n","protected":false},"excerpt":{"rendered":"<p><img loading=\"lazy\" decoding=\"async\" width=\"233\" height=\"24\" src=\"https:\/\/icrowdnewswire.com\/wp-content\/uploads\/2020\/06\/3998-ICN.png\" alt=\"\">Shining a Rust-based forensic light into the darker corners of images Boffins in Microsoft Research has pulled the covers off&nbsp;Project Freta, a free service aimed at spotting memory malfeasance. A technology demonstration named for the&nbsp;street in Warsaw, Poland where Marie Curie was born, Freta comes from the NExT Security Ventures (NSV) team and is all &hellip; <a href=\"https:\/\/icrowdnewswire.com\/2020\/07\/08\/fret-not-linux-fans-microsofts-project-freta-is-here-to-peer-deep-into-your-memory-to-spot-malware\/\">Continue reading <span>Fret not, Linux fans, Microsoft&rsquo;s Project Freta is here to peer deep into your memory&hellip; to spot malware<\/span><\/a> <a href=\"http:\/\/ipsnews.net\/business\/2020\/07\/08\/fret-not-linux-fans-microsofts-project-freta-is-here-to-peer-deep-into-your-memory-to-spot-malware\/\" class=\"more-link\">Continue Reading <span class=\"meta-nav\">&rarr;<\/span><\/a><\/p>\n","protected":false},"author":19,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[3,22,54],"tags":[],"class_list":["post-40698","post","type-post","status-publish","format-standard","hentry","category-english","category-united-states","category-wire"],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v24.9 - https:\/\/yoast.com\/wordpress\/plugins\/seo\/ -->\n<title>Fret not, Linux fans, Microsoft\u2019s Project Freta is here to peer deep into your memory\u2026 to spot malware - Business<\/title>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/ipsnews.net\/business\/2020\/07\/08\/fret-not-linux-fans-microsofts-project-freta-is-here-to-peer-deep-into-your-memory-to-spot-malware\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Fret not, Linux fans, Microsoft\u2019s Project Freta is here to peer deep into your memory\u2026 to spot malware - Business\" \/>\n<meta property=\"og:description\" content=\"Shining a Rust-based forensic light into the darker corners of images Boffins in Microsoft Research has pulled the covers off&nbsp;Project Freta, a free service aimed at spotting memory malfeasance. A technology demonstration named for the&nbsp;street in Warsaw, Poland where Marie Curie was born, Freta comes from the NExT Security Ventures (NSV) team and is all &hellip; Continue reading Fret not, Linux fans, Microsoft&rsquo;s Project Freta is here to peer deep into your memory&hellip; to spot malware Continue Reading &rarr;\" \/>\n<meta property=\"og:url\" content=\"https:\/\/ipsnews.net\/business\/2020\/07\/08\/fret-not-linux-fans-microsofts-project-freta-is-here-to-peer-deep-into-your-memory-to-spot-malware\/\" \/>\n<meta property=\"og:site_name\" content=\"Business\" \/>\n<meta property=\"article:published_time\" content=\"2020-07-08T18:20:00+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/icrowdnewswire.com\/wp-content\/uploads\/2020\/06\/3998-ICN.png\" \/>\n<meta name=\"author\" content=\"Aneesa\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"Aneesa\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"3 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\/\/schema.org\",\"@graph\":[{\"@type\":\"WebPage\",\"@id\":\"https:\/\/ipsnews.net\/business\/2020\/07\/08\/fret-not-linux-fans-microsofts-project-freta-is-here-to-peer-deep-into-your-memory-to-spot-malware\/\",\"url\":\"https:\/\/ipsnews.net\/business\/2020\/07\/08\/fret-not-linux-fans-microsofts-project-freta-is-here-to-peer-deep-into-your-memory-to-spot-malware\/\",\"name\":\"Fret not, Linux fans, Microsoft\u2019s Project Freta is here to peer deep into your memory\u2026 to spot malware - Business\",\"isPartOf\":{\"@id\":\"https:\/\/ipsnews.net\/business\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\/\/ipsnews.net\/business\/2020\/07\/08\/fret-not-linux-fans-microsofts-project-freta-is-here-to-peer-deep-into-your-memory-to-spot-malware\/#primaryimage\"},\"image\":{\"@id\":\"https:\/\/ipsnews.net\/business\/2020\/07\/08\/fret-not-linux-fans-microsofts-project-freta-is-here-to-peer-deep-into-your-memory-to-spot-malware\/#primaryimage\"},\"thumbnailUrl\":\"https:\/\/icrowdnewswire.com\/wp-content\/uploads\/2020\/06\/3998-ICN.png\",\"datePublished\":\"2020-07-08T18:20:00+00:00\",\"author\":{\"@id\":\"https:\/\/ipsnews.net\/business\/#\/schema\/person\/cee3758d3201f95199de3522858ca7e2\"},\"breadcrumb\":{\"@id\":\"https:\/\/ipsnews.net\/business\/2020\/07\/08\/fret-not-linux-fans-microsofts-project-freta-is-here-to-peer-deep-into-your-memory-to-spot-malware\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\/\/ipsnews.net\/business\/2020\/07\/08\/fret-not-linux-fans-microsofts-project-freta-is-here-to-peer-deep-into-your-memory-to-spot-malware\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\/\/ipsnews.net\/business\/2020\/07\/08\/fret-not-linux-fans-microsofts-project-freta-is-here-to-peer-deep-into-your-memory-to-spot-malware\/#primaryimage\",\"url\":\"https:\/\/icrowdnewswire.com\/wp-content\/uploads\/2020\/06\/3998-ICN.png\",\"contentUrl\":\"https:\/\/icrowdnewswire.com\/wp-content\/uploads\/2020\/06\/3998-ICN.png\"},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\/\/ipsnews.net\/business\/2020\/07\/08\/fret-not-linux-fans-microsofts-project-freta-is-here-to-peer-deep-into-your-memory-to-spot-malware\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\/\/ipsnews.net\/business\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Fret not, Linux fans, Microsoft\u2019s Project Freta is here to peer deep into your memory\u2026 to spot malware\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\/\/ipsnews.net\/business\/#website\",\"url\":\"https:\/\/ipsnews.net\/business\/\",\"name\":\"Business\",\"description\":\"\",\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\/\/ipsnews.net\/business\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Person\",\"@id\":\"https:\/\/ipsnews.net\/business\/#\/schema\/person\/cee3758d3201f95199de3522858ca7e2\",\"name\":\"Aneesa\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\/\/ipsnews.net\/business\/#\/schema\/person\/image\/\",\"url\":\"https:\/\/secure.gravatar.com\/avatar\/5635ace541744f4e232d93d2fafa63d478ed1fd5c863cbc1484fc2148961368f?s=96&d=mm&r=g\",\"contentUrl\":\"https:\/\/secure.gravatar.com\/avatar\/5635ace541744f4e232d93d2fafa63d478ed1fd5c863cbc1484fc2148961368f?s=96&d=mm&r=g\",\"caption\":\"Aneesa\"},\"sameAs\":[\"https:\/\/icrowdnewswire.com\/fc\"],\"url\":\"http:\/\/ipsnews.net\/business\/author\/aneesa\/\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"Fret not, Linux fans, Microsoft\u2019s Project Freta is here to peer deep into your memory\u2026 to spot malware - Business","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/ipsnews.net\/business\/2020\/07\/08\/fret-not-linux-fans-microsofts-project-freta-is-here-to-peer-deep-into-your-memory-to-spot-malware\/","og_locale":"en_US","og_type":"article","og_title":"Fret not, Linux fans, Microsoft\u2019s Project Freta is here to peer deep into your memory\u2026 to spot malware - Business","og_description":"Shining a Rust-based forensic light into the darker corners of images Boffins in Microsoft Research has pulled the covers off&nbsp;Project Freta, a free service aimed at spotting memory malfeasance. A technology demonstration named for the&nbsp;street in Warsaw, Poland where Marie Curie was born, Freta comes from the NExT Security Ventures (NSV) team and is all &hellip; Continue reading Fret not, Linux fans, Microsoft&rsquo;s Project Freta is here to peer deep into your memory&hellip; to spot malware Continue Reading &rarr;","og_url":"https:\/\/ipsnews.net\/business\/2020\/07\/08\/fret-not-linux-fans-microsofts-project-freta-is-here-to-peer-deep-into-your-memory-to-spot-malware\/","og_site_name":"Business","article_published_time":"2020-07-08T18:20:00+00:00","og_image":[{"url":"https:\/\/icrowdnewswire.com\/wp-content\/uploads\/2020\/06\/3998-ICN.png","type":"","width":"","height":""}],"author":"Aneesa","twitter_card":"summary_large_image","twitter_misc":{"Written by":"Aneesa","Est. reading time":"3 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"WebPage","@id":"https:\/\/ipsnews.net\/business\/2020\/07\/08\/fret-not-linux-fans-microsofts-project-freta-is-here-to-peer-deep-into-your-memory-to-spot-malware\/","url":"https:\/\/ipsnews.net\/business\/2020\/07\/08\/fret-not-linux-fans-microsofts-project-freta-is-here-to-peer-deep-into-your-memory-to-spot-malware\/","name":"Fret not, Linux fans, Microsoft\u2019s Project Freta is here to peer deep into your memory\u2026 to spot malware - Business","isPartOf":{"@id":"https:\/\/ipsnews.net\/business\/#website"},"primaryImageOfPage":{"@id":"https:\/\/ipsnews.net\/business\/2020\/07\/08\/fret-not-linux-fans-microsofts-project-freta-is-here-to-peer-deep-into-your-memory-to-spot-malware\/#primaryimage"},"image":{"@id":"https:\/\/ipsnews.net\/business\/2020\/07\/08\/fret-not-linux-fans-microsofts-project-freta-is-here-to-peer-deep-into-your-memory-to-spot-malware\/#primaryimage"},"thumbnailUrl":"https:\/\/icrowdnewswire.com\/wp-content\/uploads\/2020\/06\/3998-ICN.png","datePublished":"2020-07-08T18:20:00+00:00","author":{"@id":"https:\/\/ipsnews.net\/business\/#\/schema\/person\/cee3758d3201f95199de3522858ca7e2"},"breadcrumb":{"@id":"https:\/\/ipsnews.net\/business\/2020\/07\/08\/fret-not-linux-fans-microsofts-project-freta-is-here-to-peer-deep-into-your-memory-to-spot-malware\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/ipsnews.net\/business\/2020\/07\/08\/fret-not-linux-fans-microsofts-project-freta-is-here-to-peer-deep-into-your-memory-to-spot-malware\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/ipsnews.net\/business\/2020\/07\/08\/fret-not-linux-fans-microsofts-project-freta-is-here-to-peer-deep-into-your-memory-to-spot-malware\/#primaryimage","url":"https:\/\/icrowdnewswire.com\/wp-content\/uploads\/2020\/06\/3998-ICN.png","contentUrl":"https:\/\/icrowdnewswire.com\/wp-content\/uploads\/2020\/06\/3998-ICN.png"},{"@type":"BreadcrumbList","@id":"https:\/\/ipsnews.net\/business\/2020\/07\/08\/fret-not-linux-fans-microsofts-project-freta-is-here-to-peer-deep-into-your-memory-to-spot-malware\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/ipsnews.net\/business\/"},{"@type":"ListItem","position":2,"name":"Fret not, Linux fans, Microsoft\u2019s Project Freta is here to peer deep into your memory\u2026 to spot malware"}]},{"@type":"WebSite","@id":"https:\/\/ipsnews.net\/business\/#website","url":"https:\/\/ipsnews.net\/business\/","name":"Business","description":"","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/ipsnews.net\/business\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Person","@id":"https:\/\/ipsnews.net\/business\/#\/schema\/person\/cee3758d3201f95199de3522858ca7e2","name":"Aneesa","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/ipsnews.net\/business\/#\/schema\/person\/image\/","url":"https:\/\/secure.gravatar.com\/avatar\/5635ace541744f4e232d93d2fafa63d478ed1fd5c863cbc1484fc2148961368f?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/5635ace541744f4e232d93d2fafa63d478ed1fd5c863cbc1484fc2148961368f?s=96&d=mm&r=g","caption":"Aneesa"},"sameAs":["https:\/\/icrowdnewswire.com\/fc"],"url":"http:\/\/ipsnews.net\/business\/author\/aneesa\/"}]}},"amp_enabled":true,"_links":{"self":[{"href":"http:\/\/ipsnews.net\/business\/wp-json\/wp\/v2\/posts\/40698","targetHints":{"allow":["GET"]}}],"collection":[{"href":"http:\/\/ipsnews.net\/business\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"http:\/\/ipsnews.net\/business\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"http:\/\/ipsnews.net\/business\/wp-json\/wp\/v2\/users\/19"}],"replies":[{"embeddable":true,"href":"http:\/\/ipsnews.net\/business\/wp-json\/wp\/v2\/comments?post=40698"}],"version-history":[{"count":1,"href":"http:\/\/ipsnews.net\/business\/wp-json\/wp\/v2\/posts\/40698\/revisions"}],"predecessor-version":[{"id":40699,"href":"http:\/\/ipsnews.net\/business\/wp-json\/wp\/v2\/posts\/40698\/revisions\/40699"}],"wp:attachment":[{"href":"http:\/\/ipsnews.net\/business\/wp-json\/wp\/v2\/media?parent=40698"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"http:\/\/ipsnews.net\/business\/wp-json\/wp\/v2\/categories?post=40698"},{"taxonomy":"post_tag","embeddable":true,"href":"http:\/\/ipsnews.net\/business\/wp-json\/wp\/v2\/tags?post=40698"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}