Strengthening our malware analysis capabilities
ID: e0f4fd0c-066f-5e5a-8cb2-1da9b8fcc9f9
STIX ID: report--e0f4fd0c-066f-5e5a-8cb2-1da9b8fcc9f9
Feed Name: CERT Polska
The report announces enhancements to Cuckoo Sandbox developed with Hatching.io, including the Onemon module for YARA-triggered process memory dumping (e.g., during process creation, NtResumeThread/process hollowing, or termination) and new static configuration extraction for items like C2s, keys, and DGA seeds. It also introduces the Roach library to streamline operations on process dumps (decompression, decryption, hashing, serialization, PE parsing) and notes availability of analysis results via the mwdb platform as part of the SOASP project.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
