Cuckoo Sandbox Overview and Demo

  Рет қаралды 69,404

Chad Yantorno

Chad Yantorno

Күн бұрын

Пікірлер
@TheCrookedPenguin
@TheCrookedPenguin 7 жыл бұрын
This presentation is extremely helpful and detailed. Mr Yantorno explains everything with great detail. Also, this is a must-see video from anyone starting out with cuckoo. You helped me immensely, thank you very much.
@pbr3s
@pbr3s 5 жыл бұрын
7:28 "you're inside a simulation of a simulation [...]"
@TheSoDHater
@TheSoDHater 7 жыл бұрын
The male wares got me rolling though.
@mmm-me4kk
@mmm-me4kk 2 жыл бұрын
Hello, thank you for the presentation. Now Cuckoo is outdated and not really in use anymore, do you know some good alternatives?
@rajrana-qx2on
@rajrana-qx2on Жыл бұрын
Thank you so much, Would you able to provide this slide/presentation by any chance?
@dvdjonny
@dvdjonny 6 жыл бұрын
Hey... Thanks for sharing this! is there anywhere I can read your Presentation online?
@patrickkirchner4464
@patrickkirchner4464 7 жыл бұрын
Was that XP VM automatically reverted to the snapshot after each of the the malware samples was analyzed or would you need to manually do that?
@maximumrpg3707
@maximumrpg3707 7 жыл бұрын
Are you ever going to do more videos like this? Stuff like this is always interesting.
@Puvipavan
@Puvipavan 4 жыл бұрын
Can't you change system date to fast forward it when malware sleeps for 2 days?
@manoharbaratam8792
@manoharbaratam8792 6 жыл бұрын
Nice video Yantorno, this is a must watch video for beginners of Cuckoo and can get a clear cut idea about what it is and how it works,. Please upload your presentation and the URL's in Video description which help people to directly view instead of pausing the video and typing it. Great work, really appreciated and please do make more videos like this
@pashkaewall8857
@pashkaewall8857 6 жыл бұрын
has anyone had any experience of taking action against a party whose repeatly sent metaexploited files to the opposition party in a litigation case?
@jimivie
@jimivie 3 жыл бұрын
Not too many videos on YouTUbe over an hour I finish....nice work
@allanng78
@allanng78 7 жыл бұрын
Hi, Did you install any addition prior to this demonstration?
@absentfromtheworld
@absentfromtheworld 7 жыл бұрын
Is it possible to setup and use Cuckoo without a virtualmachine running windows?
@warrenperez9312
@warrenperez9312 7 жыл бұрын
I have been trying to install cuckoo on ubuntu but when running cuckoo and passing the malware using submit.py, cuckoo is unable to startup the virtual machine. Any ideas?
@dansharvit725
@dansharvit725 5 жыл бұрын
Can you run different AV's on each VM to test them against the malware?
@bennybenassi9497
@bennybenassi9497 8 жыл бұрын
Hi Chad, thank you for this Video. How did you get results for Hosts, DNS, Network (40:55), HTTP/HTTPS, TCP (42:22), because I get only UDP?
@brianjigg6697
@brianjigg6697 7 жыл бұрын
How to add signature in cuckoo library? I have created a new signature for a ransomware and want to add it in cuckoo.
@BhavdeepSinghSachdeva
@BhavdeepSinghSachdeva 8 жыл бұрын
Is there some support for converting cuckoo json files created to MIST(Malware Instruction Sets) for machine learning analysis of these files.
@wshep17
@wshep17 7 жыл бұрын
any success?
@EngMohannad1
@EngMohannad1 7 жыл бұрын
Thanks, very useful. Can I use Cuckoo for analyzing ELF binaries?
@360dom360
@360dom360 7 жыл бұрын
Do you have a download for any of the files you uploaded? I would like to go through some of these myself (running linux so no worries about getting a windows machine infected)
@emilhozan71
@emilhozan71 6 жыл бұрын
I'm pretty sure he directed you to the GitHub repo.
@joyprakashsharma8234
@joyprakashsharma8234 5 жыл бұрын
Mongodb isn't a fork of MySQL, The fork is MariaDB
@rizkimaulana4645
@rizkimaulana4645 5 жыл бұрын
Hey, anyone know which one is called "system call"??
@grootgroot1929
@grootgroot1929 2 жыл бұрын
Hi, You used guest vms inside cuckoo-vm. Can we have guest vm outside cuckoo vm? For ex. create 2 vms in virtual box. vm1 as cuckoo vm. vm2 as guest vm. Query open to everyone.
@yashkhandelwalhyd
@yashkhandelwalhyd 8 жыл бұрын
Is there a way, I can get this presentation ??
@michaelkasede1489
@michaelkasede1489 6 жыл бұрын
Hi, great presentation. This presentation clearly should get more views and likes. Not to worry, many people out there are not cut out for this kind of work. Kudos mate!!
@shamimlimon7585
@shamimlimon7585 8 жыл бұрын
I am try to configure this but after load http: 127.0.0.1:8000 error message like this"""Template doesn't exit"" in web page. please help me..
@emilhozan71
@emilhozan71 6 жыл бұрын
did you run the two scripts required? what about rebooting the machines?
@Juan-je3ml
@Juan-je3ml 8 жыл бұрын
Mongo is not a fork of Mysql. you are referring to mariadb. Yara looks at characteristics of a certain file, not behavior. New version of cuckoo is also able to automatically implement ip tables for you so that you car have different exits. Also depending on your distro you might be falling behind on kernel upgrades due using apt upgrade instead of dist-upgrade (depends on your hardware enablement stack). just 2 cents.
@chadyantorno
@chadyantorno 8 жыл бұрын
Thanks for your comment. I was talking for about an hour and it's possible I misspoke in some instances. This video wasn't about Linux and kernel upgrades, it was about Cuckoo.
@blusteel28
@blusteel28 7 жыл бұрын
Awesome video, thanks for posting!
@steveswitzer4353
@steveswitzer4353 6 жыл бұрын
Great many thanks i am going to try and get this up and working for my organisation
@wrcz
@wrcz 3 жыл бұрын
Chad Yantorno vs Virgin Malware
@kognitiva
@kognitiva 5 жыл бұрын
Dont think that MongoDB is a fork of MySql. It's not the "same exact thing" :)
@navjotsingh2251
@navjotsingh2251 4 жыл бұрын
Yeah, it is not a fork. They are very different. MySQL is a relational database and mongo is a non relational database, their languages are very different too.
@TheEggroll4321
@TheEggroll4321 5 жыл бұрын
Good job! Very helpful
@und3rgr0undfr34k
@und3rgr0undfr34k 5 жыл бұрын
awesome !
@ibnomer342
@ibnomer342 8 жыл бұрын
Thank you!
@ca7986
@ca7986 3 жыл бұрын
❤️👌
@jfoter
@jfoter 7 жыл бұрын
You lost me when you presented wrong facts. MariaDB is the form of MySQL after the Oracle purchase. Mongo is not a relational database like MySQL and MariaDB; Mongo is a Document based NoSQL database.
@jfoter
@jfoter 7 жыл бұрын
:s/Form/fork/
@chadyantorno
@chadyantorno 7 жыл бұрын
Thanks for the clarification. I'm always learning and it's possible I misspoke or was incorrect in some instances.
@emilhozan71
@emilhozan71 6 жыл бұрын
Do those technicalities really matter though? Have you put out any work regarding anything? By no means am I excusing his errors but it's not easy putting content out for fear of such scrutiny. The video wasn't about the history of MongDB / Linux commands / or anything OTHER THAN Cuckoo. Do you have any feedback about that, or did you stop it just to comment?
Open Source Malware Lab - Robert Simmons
49:41
Security BSides London
Рет қаралды 13 М.
Malware Analysis - Static, Dynamic and Code Analysis
43:41
Karthikeyan Ragunathan
Рет қаралды 29 М.
Жездуха 42-серия
29:26
Million Show
Рет қаралды 2,6 МЛН
Война Семей - ВСЕ СЕРИИ, 1 сезон (серии 1-20)
7:40:31
Семейные Сериалы
Рет қаралды 1,6 МЛН
Cuckoo Install - Your Own Malware Sandbox!
45:58
Taylor Walton
Рет қаралды 54 М.
Security: Malware Analysis
1:08:16
Bill Buchanan OBE
Рет қаралды 42 М.
Malware Analysis Part #1: Basic Static Analysis
50:49
Candan BOLUKBAS
Рет қаралды 58 М.
Practical Malware Analysis Essentials for Incident Responders
50:49
RSA Conference
Рет қаралды 151 М.
MALWARE ANALYSIS // How to get started with John Hammond
55:45
David Bombal
Рет қаралды 295 М.
How To Setup A Sandbox Environment For Malware Analysis
18:17
HackerSploit
Рет қаралды 265 М.
Juriaan Bremer: Cuckoo Sandbox: State-of-the-art Automated Malware Analysis (en)
57:19
FH St. Pölten – University of Applied Sciences
Рет қаралды 10 М.
IDA Pro Malware Analysis Tips
1:38:17
OALabs
Рет қаралды 117 М.