Effective cloud sandbox detection from ring 3
-
Updated
Jan 17, 2024 - C
Effective cloud sandbox detection from ring 3
Unwanted Execution Prevention - (Virustotal, etc)
Malvm is a tool to create modified Windows 10/ 7 virtual machines, where malware is not able to detect its virtual environment. Those VMs can be used to analyze malware.
Public malware techniques used in the wild: Virtual Machine, Emulation, Debuggers, Sandbox detection.
This repository contains the c# code which is using latest persistence technique and multiple anti-vm, anti-sandboxes techniques. Creating persistence by using WindowsApps folder, schtasks, powershell cmdlet (Get-Variable).
A trojan downloader which will download any file using a direct download link stealthily. The final size of the payload will be less than 10 mb.
Apate performs anti-debugging, anti-VM and anti-sandbox tests, to see if your linux system is able to stay under the radar.
Windows-based implementation of several anti-vm techniques used in malware development.
A pintool for protecting a sandbox application of common anti-virtualmachine and anti-sandbox detection techniques
#seccamp 2014 CTF softsec (Reverse 400pt)
MinegamesAntiCheat Are an Advanced C# Anti-Cheat Library which prevents debug attaching, dll-injection, etc..... and it can communicate with your server.
EQU8 User-Mode Bypass and Injector
Some anti QEMU trick used by in-the-wild malware.
Detects virtual machines and malware analysis environments
This script allows you to create various artifacts on a bare-metal Windows computer in an attempt to trick malwares that looks for VM or analysis tools
Evasions encyclopedia gathers methods used by malware to evade detection when run in virtualized environment. Methods are grouped into categories for ease of searching and understanding. Also provided are code samples, signature recommendations and countermeasures within each category for the described techniques.
Add a description, image, and links to the anti-vm topic page so that developers can more easily learn about it.
To associate your repository with the anti-vm topic, visit your repo's landing page and select "manage topics."