kevoreilly / CAPEv2

Malware Configuration And Payload Extraction
https://capesandbox.com/analysis/
Other
2.01k stars 425 forks source link

Clarification: Does CAPEv2 automatically create VMs? #2102

Closed joser12345678 closed 6 months ago

joser12345678 commented 6 months ago

Hello,

I am new to cape and while setting it up in my environment I noticed there are some windows VMs that seem to have been created from CAPE, I tried to search the source code for the names of the VMs because I thought maybe CAPE creates these automatically. Below is the VM list:

~$ sudo virsh list --all
 Id   Name                 State
-------------------------------------
 1    myvm                 running
 -    windows10-cuckoo01   shut off
 -    windows10-cuckoo02   shut off
 -    windows10-cuckoo03   shut off
 -    windows10-cuckoo04   shut off
 -    windows10-cuckoo05   shut off
 -    windows10-cuckoo06   shut off
 -    windows7-cuckoo01    shut off
 -    windows7-cuckoo02    shut off
 -    windows7-cuckoo03    shut off
 -    windows7-cuckoo04    shut off
 -    windows7-cuckoo05    shut off
 -    windows7-cuckoo06    shut off
 -    windows7-cuckoo07    shut off
 -    windows7-cuckoo08    shut off
 -    windows7-cuckoo09    shut off
 -    windows7-cuckoo10    shut off
 -    windows7-cuckoo11    shut off
 -    windows7-cuckoo12    shut off
 -    windows7-cuckoo13    shut off
 -    windows7-cuckoo14    shut off
 -    windows7-cuckoo15    shut off
 -    windows7-cuckoo16    shut off
 -    windows7-cuckoo17    shut off
 -    windows7-cuckoo18    shut off
 -    windows7-cuckoo19    shut off
 -    windows7-cuckoo20    shut off

I am just looking for clarification on if CAPE does this be default. It should also be noted that these VMs seem to have snapshots in each of them.

Thank you in advance!

doomedraven commented 6 months ago

hello, no we don-t create any VM, is totally your job to do that