You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
I have cloned cuckoomonitor in the monitor directory of Cuckoo Sandbox, after I do make, and when I run pafish on windows7, nothing was changed..
So, What should I do to hide my virtual environment?
And the hook_reg.c file no longer exists?
The text was updated successfully, but these errors were encountered:
Well, the DLLs that you'll find in the Cuckoo Community are literally just the compiled version of what you'll find in this repository. The hook_reg.c file was changed around and is now mostly represented by sigs/registry.rst and sigs/registry_native.rst. Feel free to experiment with hiding certain items and if you have anything that you'd like to share back, do let us know.
Hi! I am new to cuckoomonitor. I stumbled on this problem also. Is there an example on how to convert the code from hook_reg.c to be used in registry.srt.
For example I want to bypass VM detection that uses RegOpenKeyExA and checks for lpSubkey as "VirtualBox". How would I go about inserting that bypass in sigs/registry.rst?
I have cloned cuckoomonitor in the monitor directory of Cuckoo Sandbox, after I do make, and when I run pafish on windows7, nothing was changed..
So, What should I do to hide my virtual environment?
And the hook_reg.c file no longer exists?
The text was updated successfully, but these errors were encountered: