In-Memory Webshell
A backdoor loaded and executed inside a running process without being written to disk as a file. Because no file exists for scanners to detect, it must be hunted through process behavior, memory analysis, and logs rather than file signatures.