Memory analysis - VAD tags and code injection

Viewed 3567

I'm doing a research about memory forensics, and currently I need to learn about ways to find code injections in the memory by a several number of techniques. One of the ways is involving the use of VAD tags for code injection.

I tried to find out exactly what VAD is and what are VAD tags, but I just couldn't find a good simple explanation. The only thing I understand is that VAD is some kind of a win32 structure, and it got something to do with a process's address space. But I don't understand what exactly VAD does, how you use it to inject your code, and how can you discover code injections in the RAM that use VAD tags.

I'd appreciate it if you guide me through this. Thanks :)

2 Answers

Thread is old but I found good explanation of VAD's. It would partially answer your question.

This link gives insight of the VAD and some more info regarding the data structure used along with good snapshots.

*Virtual Address Descriptors can provide useful information about the address space of a specified process. They provide information about the PTE Protection Bits, inheritance of the page and wherever the page is being shared among between processes.

VAD Trees are based upon a programming algorithm called a AVL Tree, an example and explanation of one can be found here on Sysnative. Further description in link*

Virtual Address Discriptors

Related