CybercentreCanada / assemblyline

AssemblyLine 4: File triage and malware analysis
https://cybercentrecanada.github.io/assemblyline4_docs/
MIT License
243 stars 15 forks source link

VMRay Service #56

Open cccs-rs opened 1 year ago

cccs-rs commented 1 year ago

Is your feature request related to a problem? Please describe. Has been requested over the years but there is no official service because of the license requirements & lack of API documentation: VMRay integration (google.com)

Describe the solution you'd like Community-written service to leverage VMRay analysis

eljeffeg commented 1 year ago

We've started work on this and should be able to upload something after testing and including the standard dynamic heuristics.

ed4wg commented 1 year ago

@eljeffeg - we're also interested in integrating with VMRay? Any luck on this service?

eljeffeg commented 1 year ago

Yes, but we're dealing with issues with VMRay itself. The dynamic piece isn't working as the win11 vms are failing to start. Once we get that all figured out, we'll continue working on the AL service.

mback2k commented 8 months ago

@eljeffeg any update on your side? We also have a VMRay instance and would like to see a service developed. Before we start from scratch, maybe we can join forces?

eljeffeg commented 8 months ago

@ed4wg @mback2k We haven't been able to finish it as we've been busy with other things, but here is what we have thus far, which should at least pull back results and such. Happy to join forces and get it done. https://github.com/fbicyber/assemblyline-service-vmray

Note: we don't actually have a container on dockerhub, so you'll have to build your own.