The rise of attacks using fileless malware and other forensics-fighting measures is creating a bigger-than-ever skills gap in the cybersecurity industry.
Increasingly, bad actors are using techniques that leave little trace on physical drives. And unfortunately, white hats aren’t keeping up: There’s a shortage of digital forensics professionals who can investigate these types of attacks.

According to Alissa Torres, founder of Sibertor Forensics and former member of the MANDIANT Computer Incident Response Team (MCIRT), “Attackers know how forensic investigators work and are getting better at using methods that leave minimal traces behind—we’re in a constant race, where the key difference is education.”
Over the past year, Torres said she has seen an increase in fileless malware, which exists only in volatile memory and avoids installing itself on a target’s file system.
The SANS Institute estimates that perhaps one in four digital forensics and incident response professionals (DFIRs) have the appropriate level of education to successfully analyze the new kinds of self-defense techniques, which include more sophisticated rootkits and anti-memory analysis mechanisms.
“The field of memory forensics exploded around 2005, when many of the analysis tools began to become available, and their use in forensics has increased since then,” Torres explained.
Although the tools have improved, Torres also emphasized that “having a hammer and a saw does not make you a carpenter. A deeper understanding of the internal operating system, including memory management, allows the examiner to access the target data specifically for the needs of the case at hand.”
