Personally, I try to keep it to between 5 and 8 minutes, not because I don't have the time, but to make the video more dynamic.
I could also do a 30min video, but I know everyone will fall asleep... (and I put on some good music
^^ )
What is also important is to add a conclusion at the end. Many VT don't (forcing people to watch to whole boring video). Cruel sister always adds a script in the beginning (what was tested). Your video's sort of always follow the same procedure, so after having watched many of your video's I know by now.
May I be so cheeky to suggest a change? You video's are of a better quality than all other YT I have seen, but you are still following the same procedure those Youtube Testers do. To set yourself apart from them, you should consider a change of testing procedure. May I suggest a small adoption and a major addition?
The procedure most Youtube testers follow is
- a manual 1-by-1 URL block test
- a scan on a folder with malware (a 'malware ZOO')
- a scripted gangbang on the remainder of that folder (not removed by the scan)
- run some second opinion scanners to check what is left/missed
- release the video
Small adoption: What I would like to know is how the missed downloaded samples would be handled by the tested product
- a manual 1-by-1 URL block test
- add the downloaded samples of the missed URL blocks to the folder of your malware collection
- a scan on a folder with malware
- a scripted gangbang on the remainder of that folder (missed by URL block and scan)
- run some second opinion scanners to check what is left/missed
- add a Cruel Sister recap with found traces and infections (of the above scans) plus active processes with a VT-score (using process explorer) of +1 (possible FP) and +5 (malware)
- release the video (luckily you fast forward and edit your video's
)
Major addition: I know one professional testing agency also checks what samples are recognized a day later
-
wait a day and bring virtual box back to the 'after the URL test' state
- a text intro (like Cruel Sister always does) summarizing the results of previous test
- a scripted gangbang on the remainder of that folder (missed by URL block and scan)
- run some second opinion scanners to check what is left/missed
- a text conclusion/summary (like Cruel Sister always does) on the differences in results between 0-day and 1-day
- release the follow up video
This way you could re-use some of your hard work and double your content production (and hopefuly traffic also).