cuckoosandbox / community

Repository of modules and signatures contributed by the community
323 stars 175 forks source link

Customize Cuckoo Result #292

Open Huthifh opened 7 years ago

Huthifh commented 7 years ago

how can I customize the cuckoo result juat to make a single result if it malware or not ?

doomedraven commented 7 years ago

https://cuckoo.sh/docs/customization/reporting.html

Huthifh commented 7 years ago

Dear Sir. I read it befor and I still dont know how to do that. If you have an idea could you please explane it here !!!!

doomedraven commented 7 years ago

you can use the result of suricata/yara/volatility custom plugins/VTs/community signatures/whatever, but be aware it can also generate FPs

play with reports and select data which you trust

Huthifh commented 7 years ago

I went to implement an automated system. I went cuckoo to deliver a single result to other system. can cuckoo generte automated result like this ?

jbremer commented 7 years ago

@Huthifh Cuckoo isn't a solution to provide you a 100% accurate yes/no answer. If you want to work towards that there's plenty of work that we could do together in that direction, but as-is what you're asking isn't something we support or suggest users to do.

Huthifh commented 7 years ago

@jbremer @doomedraven thanks a lot for your reply. now I am targeting the other system that will take a feed back from cuckoo, now I am not focusing on how much cuckoo accurate I just need a single result. My next work will be in cuckoo and I have tow idea that will enhance cuckoo very much and I hope to work together in that. Best regard

doomedraven commented 7 years ago

great, goodies is always good :)