Thread Rating:
  • 0 Vote(s) - 0 Average
  • 1
  • 2
  • 3
  • 4
  • 5
Mandiant's CAPA + GoReSym to reinforce VT's capabilities
#1
Information 
Quote:
[Image: Logo_VT_Horizontal.png]

VirusTotal, the world’s largest crowdsourced threat intelligence platform, is made possible thanks to a large community of security practitioners and vendors who integrate into our platform their best security tools. We are happy to announce the inclusion of two remarkable additions, both already having wide acceptance in the security community: Capa and GoReSym from Mandiant’s FLARE team.

CAPA

Capa provides a human readable explanation of what a suspicious binary might do and describes the evidence that it found. This gives analysts a high level understanding without the need of going into time consuming Reverse Engineering. We now run Capa against all PE and ELF files submitted to VirusTotal and display the results under the behavior tab.

[Image: c_K_5JKdT2xN8LKiIujY8tw3p8XCsnbf-TUa03-d...kvA=s16000]

Here you can find an example:

https://www.virustotal.com/gui/file/5689...d/behavior

Because we map the Capa results into ATT&CK Tactics and Techniques, you can pivot across them, making it easy to find other malware samples with the same behaviors. You can also create YARA rules for VirusTotal LiveHunt to get notified when any new file matching the same ATT&CK Tactics and Techniques is uploaded to VirusTotal. For example:

import "vt"

rule capa_mitre_attack_techniques {
condition:

for 2 vt_behaviour_mitre_attack_techniques in vt.behaviour.mitre_attack_techniques: (
vt_behaviour_mitre_attack_techniques.id == "T1222" // set file attributes
or vt_behaviour_mitre_attack_techniques.id == "T1083" // get file system object information
)
}


When contributing to the Capa rules open source project, you’ll influence the behaviors and capabilities that VirusTotal extracts and indexes for all executables.

That’s a pretty big impact!

GoReSym

GoReSym is a very useful tool for analyzing Go samples, parsing the binary to extract all kinds of valuable metadata. Some of this information includes function names, the Go version used to compile a binary, compiler flags, and much more. The tool is designed to be resilient in the face of malformed binaries, such as those that result from manually unpacking malware samples. Below is an example of the kind of output you’ll now see from this tool in VirusTotal:

[Image: wWjroFbB2gIMafAOeIYg9eUXIK00Qwvt9e8b8Ii8...aQQ=s16000]

Here you can find an example:

https://www.virustotal.com/gui/file/7e26...0e/details
...
Continue Reading
Reply


Messages In This Thread
Mandiant's CAPA + GoReSym to reinforce VT's capabilities - by harlan4096 - 27 January 23, 08:18

Forum Jump:


Users browsing this thread: 1 Guest(s)
[-]
Welcome
You have to register before you can post on our site.

Username/Email:


Password:





[-]
Recent Posts
Kaspersky\VPN\KSOS 21.18 & KES 12.6 beta...
Kaspersky\VPN\KSOS 2...harlan4096 — 15:39
GFYI [Official] Ashampoo Snap 16 Giveaw...
"Share feedback...mjcn19 — 09:23
FastCopy 5.7.7
FastCopy 5.7.7: ...harlan4096 — 05:45
Brave 1.65.126
Release Channel 1....harlan4096 — 05:43
AMD Confirms RDNA 3+ GPU Architecture F...
AMD reaffirms Zen5-b...harlan4096 — 05:42

[-]
Birthdays
Today's Birthdays
avatar (43)centfootadoni
Upcoming Birthdays
avatar (26)akiratoriyama
avatar (46)Jerrycix
avatar (38)awedoli
avatar (80)WinRARHowTo
avatar (36)owysykan
avatar (47)beautgok
avatar (37)axuben
avatar (43)talsmanthago
avatar (29)mocetor
avatar (44)piomaibhaict
avatar (49)kingbfef
avatar (36)izenesiq
avatar (38)ihijudu
avatar (43)tiojusop
avatar (40)Damiennug
avatar (38)acoraxe
avatar (47)contjrat
avatar (39)axylisyb
avatar (42)tukrublape
avatar (39)iruqi
avatar (40)saitetib
avatar (34)ypasodiny
avatar (37)omapek
avatar (46)Geraldtuh
avatar (42)knigiJow
avatar (44)1stOnecal
avatar (48)Mirzojap
avatar (34)idilysaju
avatar (43)xclubDum
avatar (39)Stewartanilm
avatar (42)nikitaxople
avatar (38)GregoryRog
avatar (43)mediumog
avatar (38)odukoromu
avatar (44)Joanna4589

[-]
Online Staff
There are no staff members currently online.

>