drakvuf-sandbox
antivmdetection
Our great sponsors
drakvuf-sandbox | antivmdetection | |
---|---|---|
2 | 1 | |
983 | 686 | |
2.0% | - | |
8.5 | 0.0 | |
14 days ago | over 1 year ago | |
Python | Python | |
GNU General Public License v3.0 or later | MIT License |
Stars - the number of stars that a project has on GitHub. Growth - month over month growth in stars.
Activity is a relative number indicating how actively a project is being developed. Recent commits have higher weight than older ones.
For example, an activity of 9.0 indicates that a project is amongst the top 10% of the most actively developed projects that we are tracking.
drakvuf-sandbox
-
Want to setup a malware analysis Sandbox on Windows 10. Almost giving up...
Why not have a look at DRAKVUF? Supports W10 2004 guests: https://github.com/CERT-Polska/drakvuf-sandbox
-
Similar to cuckoo sandbox
Try Drakvuf Sandbox. It's actively maintained by CERT.PL team
antivmdetection
-
Security research homelab, made with <3
To avoid detection of something like a cuckoo I would use https://github.com/nsmfoo/antivmdetection and test it with https://github.com/therealdreg/anticuckoo and https://github.com/LordNoteworthy/al-khaser
What are some alternatives?
flare-vm - A collection of software installations scripts for Windows systems that allows you to easily setup and maintain a reverse engineering environment on a VM.
al-khaser - Public malware techniques used in the wild: Virtual Machine, Emulation, Debuggers, Sandbox detection.
Detect-It-Easy - Program for determining types of files for Windows, Linux and MacOS.
cowrie - Cowrie SSH/Telnet Honeypot https://cowrie.readthedocs.io
theZoo - A repository of LIVE malwares for your own joy and pleasure. theZoo is a project created to make the possibility of malware analysis open and available to the public.
qiling - A True Instrumentable Binary Emulation Framework
yarGen - yarGen is a generator for YARA rules
simplify - Android virtual machine and deobfuscator
cerberus_research - Research tools for analysing Cerberus banking trojan.
CAPEv2 - Malware Configuration And Payload Extraction
pyWhat - 🐸 Identify anything. pyWhat easily lets you identify emails, IP addresses, and more. Feed it a .pcap file or some text and it'll tell you what it is! 🧙♀️
karton - Distributed malware processing framework based on Python, Redis and S3.