Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

AV - advanced scanning #4

Open
1 of 7 tasks
0xflux opened this issue Oct 27, 2024 · 0 comments
Open
1 of 7 tasks

AV - advanced scanning #4

0xflux opened this issue Oct 27, 2024 · 0 comments
Assignees

Comments

@0xflux
Copy link
Owner

0xflux commented Oct 27, 2024

Advanced scanning features

  • Scan file created on disk for static IOCs
  • Scan file created on disk for import address table analysis
  • Scan file created on disk for malicious segments / patterns of behaviour
    • Direct PEB access
    • Bad entropy
    • Direct syscalls in user .text segments
  • Above to be integrated with the driver when instructed, aka the driver will instruct the UM engine to scan newly created files on disk for all the above features
@0xflux 0xflux self-assigned this Oct 27, 2024
@0xflux 0xflux converted this from a draft issue Oct 27, 2024
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
Status: AV Backlog
Development

No branches or pull requests

1 participant