ExoGen CyberSecurity - Security Configuration

R

Ramona

I don't know, I never got infected since everything is sandboxed. I tested in VirtualBox and it's ok (and yes, it's worth the bother), the ViruScope in version 10 is way better (I'm using is right now).

I'm not using HIPS, I just set everything to be blocked by default (sandboxed) and in Firewall to block any requests and only allow what I say. This way I used CIS for years with no issues and I test real malware on my system from time to time.

Why do you test real malware on your PC and not inside a virtual box ?
 

ExoGen CyberSecurity

Level 3
Thread author
Verified
Well-known
Sep 17, 2016
113
Because I work in computer security and when people tell me how amazing "x" product or products I tell them that we should test on our real PCs, I get 5 random samples from my honeypot and add 5 more safe files and we execute them to see how amazing the security product is.

Like you notice when you sent me a message or how I told you here Capture.PNG

Someone from work told me how amazing his setup is and he got infected by JigSaw Ransomware so ... Personally I think that most security products are useless and it's all marketing. If you notice I don't even use HIPS, I think it's enough to use some type of sandbox and WD/MSE + Windows Firewall (if you use Windows 10 smartscreen enabled) + UAC set on max.

There is an amazing trick (it's use by some hackers with njRat), you add a digital signature to the malware and you insert inside a portable app or the most common apps that are flagged as malware (7Zip,7Zip ThemeManager and many more).
 

About us

  • MalwareTips is a community-driven platform providing the latest information and resources on malware and cyber threats. Our team of experienced professionals and passionate volunteers work to keep the internet safe and secure. We provide accurate, up-to-date information and strive to build a strong and supportive community dedicated to cybersecurity.

User Menu

Follow us

Follow us on Facebook or Twitter to know first about the latest cybersecurity incidents and malware threats.

Top