antivmdetection
CAPEv2
Our great sponsors
antivmdetection | CAPEv2 | |
---|---|---|
1 | 5 | |
686 | 1,669 | |
- | - | |
0.0 | 9.9 | |
over 1 year ago | 4 days ago | |
Python | Python | |
MIT License | GNU General Public License v3.0 or later |
Stars - the number of stars that a project has on GitHub. Growth - month over month growth in stars.
Activity is a relative number indicating how actively a project is being developed. Recent commits have higher weight than older ones.
For example, an activity of 9.0 indicates that a project is amongst the top 10% of the most actively developed projects that we are tracking.
antivmdetection
-
Security research homelab, made with <3
To avoid detection of something like a cuckoo I would use https://github.com/nsmfoo/antivmdetection and test it with https://github.com/therealdreg/anticuckoo and https://github.com/LordNoteworthy/al-khaser
CAPEv2
-
Does anyone installed cuckoo sandbox recently?
https://github.com/kevoreilly/CAPEv2 is a more "production ready" solution.
-
Looking for a good alternative to AppAnyRun
CAPEv2 CUCKOO Sandbox
- Since Cuckoo is not longer officially supported and the 3.0 project revival by Hatching seems dead what sandboxes that are standalone do you use?
-
mmm ITRG is stinky
Usually Windows Defender gets false positives and I ignore them, but for good measure, I decided to scan two of the .exe files that were a part of this torrent using VirusTotal. First one picked up nothing, second one also had no detections, however: "Matches rule EternalRomance by kevoreilly from ruleset EternalRomance at https://github.com/kevoreilly/CAPEv2"
- Dynamic Analysis Tools
What are some alternatives?
al-khaser - Public malware techniques used in the wild: Virtual Machine, Emulation, Debuggers, Sandbox detection.
cuckoo3 - Cuckoo 3 is a Python 3 open source automated malware analysis system.
drakvuf-sandbox - DRAKVUF Sandbox - automated hypervisor-level malware analysis system
cuckoo - Cuckoo Sandbox is an automated dynamic malware analysis system
cowrie - Cowrie SSH/Telnet Honeypot https://cowrie.readthedocs.io
Fegaria-Remastered - Similar to my other project Fegaria, but with improved graphics, collisions and terrain generation.
theZoo - A repository of LIVE malwares for your own joy and pleasure. theZoo is a project created to make the possibility of malware analysis open and available to the public.
dumpulator - An easy-to-use library for emulating memory dumps. Useful for malware analysis (config extraction, unpacking) and dynamic analysis in general (sandboxing).
ace-firefist - Attack chain emulator. Write recipes for initial access easily