Exetools  

Go Back   Exetools > General > General Discussion

Notices

 
 
Thread Tools Display Modes
Prev Previous Post   Next Post Next
  #10  
Old 10-30-2017, 11:18
surferxyz surferxyz is offline
Friend
 
Join Date: Jan 2005
Location: Planet Earth
Posts: 77
Rept. Given: 0
Rept. Rcvd 9 Times in 4 Posts
Thanks Given: 12
Thanks Rcvd at 54 Times in 21 Posts
surferxyz Reputation: 9
All antivirus products have complicated engines with a large amount of attack surface increasing your risk. So ensure you do not add such complicated software to your TCB.

If you want to know if a particular executable is flagged as malicious, you should probably just install a few in a couple of different virtual machines, or use virustotal.

However virustotal does not have the more CPU intensive desktop versions of many antivirus and so the unpacking/emulation functionality built into most desktop antivirus is not present, so running them yourself in different virtual machines makes sense.

Awhile ago I tested a few different antivirus to see how good they were at detecting flagged code that I obfuscated with simple methods. I found that kaspersky and f-secure had the best unpacking/emulation functionality.

At the end of the day, the features you might need for your antivirus are specific to your use case. (do you need good historical signatures of DOS malware or not?) (do you need signatures for esoteric platforms like z/OS?) (do you need high quality centralized administration to manage a large corporate network?)
Reply With Quote
 

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off


Similar Threads
Thread Thread Starter Forum Replies Last Post
Black Hat USA 2017 TechLord General Discussion 4 08-31-2017 12:48
Best Antivirus Engine mantovano General Discussion 102 02-16-2011 18:13
Antivirus API just4urim General Discussion 4 02-06-2005 02:49


All times are GMT +8. The time now is 05:21.


Always Your Best Friend: Aaron, JMI, ahmadmansoor, ZeNiX, chessgod101
( Since 1998 )