How to set up SD to allow Windows Updates in Shadow Mode

Status
Not open for further replies.

SearchLight

Level 13
Thread author
Verified
Top Poster
Well-known
Jul 3, 2017
626
Would like to try SD but would like to know how to configure it to allow Windows Updates. Thanks.
 

Sephiroth Source

Level 2
Verified
Jul 13, 2015
65
Are you planning to leave Shadow Mode on constantly? I only use it when I go to test new programs or samples of malware and then disable it. I'm not sure if you can delete the Windows Update folders so that you do not roll back the updates after SD is disabled.
 

SearchLight

Level 13
Thread author
Verified
Top Poster
Well-known
Jul 3, 2017
626
Are you planning to leave Shadow Mode on constantly? I only use it when I go to test new programs or samples of malware and then disable it. I'm not sure if you can delete the Windows Update folders so that you do not roll back the updates after SD is disabled.

I see your point as a tester but some have also suggested to use SD full time to supplement one's AV/AM just in case something slips through so you can reverse it.
 

HarborFront

Level 72
Verified
Top Poster
Content Creator
Oct 9, 2016
6,140
I see your point as a tester but some have also suggested to use SD full time to supplement one's AV/AM just in case something slips through so you can reverse it.
SD is not a 100% foolproof thing just like any other virtualzation/sandboxing software. There are sandbox-evading malware

You can

1) Exit SD on shut down
2) Start SD on boot up

I use 1) on my 2 tablets so that on each start up I perform all updates, if needed, after which I then enter into Shadow Mode

Making exclusions is like punching holes through SD armor. Also, it's not immune to keyloggers from exfitrating data from your system. And you not only need to exclude files/folders but registry entries as well, if required, the latter is difficult to carry out.
 
Last edited:

ichito

Level 11
Verified
Top Poster
Content Creator
Well-known
Dec 12, 2013
542
Would like to try SD but would like to know how to configure it to allow Windows Updates. Thanks.
No sense for me to exclude location from system disk - each update for system or software can be done on real system and than you can enter SM. That's my experiences after ca 7 years of using SD.
Also, it's not immune to keyloggers from exfitrating data from your system.
Of course...SD doesn't protect against data-leaking at all...it's not designet to do so.
 
D

Deleted member 65228

samples of malware and then disable it
Watch out regarding data theft... As others have stated above, it doesn't protect your data. Malware may dump passwords auto-saved by web browsers (and decrypt them using the browsers own APIs), steal personal documents (e.g. photos), steal chat-logs (e.g. IM software), collect your name/e-mail and similar, etc.

If you're using VPN to help protect your IP address from getting into the wrong hands, well if the VPN is applied on the host where the malware is being tested, it also opens up a big opportunity for an easier kill-switch.

Would be wiser and safer to use a secondary system for malware testing (which may have SD) or a Virtual Machine in my opinion
 

Mr.X

Level 8
Verified
Well-known
Aug 2, 2014
368
Guys this thread is about a request: Windows Updates + Shadow Defender
No off-topics please.
 

Sephiroth Source

Level 2
Verified
Jul 13, 2015
65
Just said how do I use SD. As for my security: CF configurations CS, ZAM (Pandora Enabled), Windscribe VPN and SD. I think I'm fine. And really the best proposal is to update Windows and then activate Shadow Mode so I said I did not know if it was possible to delete Windows Update (folders, registry keys, etc) in SD.
 
Status
Not open for further replies.

About us

  • MalwareTips is a community-driven platform providing the latest information and resources on malware and cyber threats. Our team of experienced professionals and passionate volunteers work to keep the internet safe and secure. We provide accurate, up-to-date information and strive to build a strong and supportive community dedicated to cybersecurity.

User Menu

Follow us

Follow us on Facebook or Twitter to know first about the latest cybersecurity incidents and malware threats.

Top