Project Freta, unveiled Monday by Microsoft, is a new free service that allows users to discover rootkits and other sophisticated malware in memory snapshots of the operating system.

Currently, the cloud-based service is only functional on Linux, but Microsoft plans to soon promote it on Windows.
The goal of the new Project Freta is to provide organizations with the ability to conduct automated forensic analysis on thousands of virtual machines in search of malware, using just a snapshot.
The service leverages sensors designed to detect malware without the malware being aware of it. The technology is built so that malware cannot detect the sensor before installation and thus cannot hide, nor take steps to remove or change it, nor modify the sensor to avoid detection.
The service examines processes, global values and addresses, files in memory, debug processes, kernel components, networks, ARP tables, open files, open sockets, and Unix sockets.
Project Freta is currently available as a portal where users can upload their operating system images for analysis. The results are accessible directly in the portal or via REST and Python APIs.
In addition to adding Windows support, Microsoft plans to expand its analytics capabilities so it can use AI technology to identify new threats.
