Skip to content

dforce/cuckoo-modified

 
 

Repository files navigation

This is a heavily modified version of Cuckoo Sandbox provided under the GPL by Accuvant, Inc.

It offers a number of advantages over the upstream Cuckoo:

  • Fully-normalized file and registry names
  • 64-bit analysis
  • Handling of WoW64 filesystem redirection
  • Many additional API hooks
  • Service monitoring
  • Correlates API calls to malware call chains
  • Ability to follow APC injection and stealth explorer injection
  • Pretty-printed API flags
  • Per-analysis Tor support
  • Over 60 new signature modules
  • Anti-anti-sandbox and anti-anti-VM techniques built-in
  • More stable hooking
  • Ability to restore removed hooks
  • Greatly improved behavioral analysis and signature module API
  • Hundreds of other bugfixes

For more information on the initial set of changes, see: http://www.accuvant.com/blog/improving-reliability-of-sandbox-results An updated blog post covering more recent changes is forthcoming.

If you want to contribute to development, submit pull requests or email [email protected].

About

Modified edition of cuckoo

Resources

Stars

Watchers

Forks

Releases

No releases published

Packages

No packages published

Languages

  • Python 91.2%
  • HTML 7.8%
  • JavaScript 0.6%
  • CSS 0.2%
  • Shell 0.2%
  • Visual Basic .NET 0.0%