cuckoosandbox / cuckoo

Cuckoo Sandbox is an automated dynamic malware analysis system
http://www.cuckoosandbox.org
Other
5.55k stars 1.71k forks source link

What do you expect to be able to search in Cuckoo? #1339

Open jbremer opened 7 years ago

jbremer commented 7 years ago

This is a general question for our users: what do you want to be able to search in Cuckoo Web interface? We're currently rebuilding our search capabilities and fulfilling our users needs would be a great way to make search as useful as possible. Please leave us a note here or privately and we'll add it to the list of search possibilities. See also #1327 for the actual issue on the new searching. Keep in mind that we will be doing a combination of searching in MongoDB and (optionally) ElasticSearch, so some searches may be limited to users running ElasticSearch.

List of searchable indicators so far:

doomedraven commented 7 years ago

Process arguments params would be great too

Maijin commented 7 years ago

Be able to search on All Strings from the memory

doomedraven commented 7 years ago

Search in buffers/arguments in behavior?

lehuff commented 7 years ago

Searching for partial registry keys would be great, same with files/paths that have been accessed/deleted/dropped. These two types of searches would probably be restricted to ES though.

SparkyNZL commented 7 years ago

Most of the things in the static analysis as this is what I use to finger print malware families.

juju4 commented 7 years ago

go more into behavioral indicators like

Thanks for the great work and sharing with community!

SparkyNZL commented 7 years ago

Would be great to have the signed malware cert info in here to :) eg serial number and MD5 of the cert company etc

SparkyNZL commented 7 years ago

yara results,

hunterbr72 commented 7 years ago

define a closer search scope, e.g. find this string in the API call parameter FILE