Updated EDR Sheet

August 4, 2017 in EDR

Just a quick update to include Nuix.

Thanks to Stuart for providing this!

If you need any explanation on the meaning of the columns, please read this post.

The updated sheet can be downloaded here.

If you spot any mistake or feel there is something missing, please do not hesitate to contact me.

Enter Sandbox: Special edition

August 3, 2017 in Sandboxing, Silly

I recently wrote Cyber version of Orgasmatron. Writing one for Metallica’s Enter Sandman was on my mind for much longer since it’s almost impossible not to think of it when you read the title of this series… So… here it is:

Enter Sandbox

QEMU, VMWare
Don’t forget the Xen
And Sandboxie’s there

Virtual Box, Cuckoo rocks
Parallels’s in stock
Till the Sandbox he comes

Sleep is nopped and faster
Cursor is moving too

Exit: Threads
Enter: Creds
Fakenet snoops
While we patch the stalling loops

Something’s wrong, freeze the guest
Heavy loaded host
And it’s not doing its best

Mining coins, WannaCry
Virus spreads like fire
And the Pafish will bite

Sleep is nopped and faster
Cursor is moving too

Exit: Threads
Enter: Creds
Fakenet snoops
While we patch the stalling loops

Now I call the function Sleep
Time Stamp Counter I will keep
If I delta some of it
Numbers bad? It’s time to quit

Hash the file, and check the strings
And never mind that noise you see
It’s just the fake I, O and C
In your report, for VP

Exit: Threads
Enter: Creds
Calling rand()

Exit: Threads
Enter: Creds
Fakenet snoops
While we patch the stalling loops