Hey everyone, I hosted a nearly 4-hour livestream to showcase the new version of CIS, find out if anything changed beyond the name and terms like HIPS and EDR, and put CIS to the test against 299 malware samples—ranging from zero-days to "one-day" exploits.
Here are the tests and results:
1) CIS updates + CIS 2027 vs. the old exploit: CIS had been updated and protected against the PoC, even with all its modules disabled except for Auto-Containment (I mean *all* of them, even script analysis);
2) CIS 2027 vs. 299 malware samples (without Auto-Containment or Cloud Analysis): Its AV identified just over 100 samples, while the rest fluctuated between execution and offline identification;
3) CIS 2027 vs. the same 299 malware samples (without the antivirus module, but with Auto-Containment + Firewall + WebLookUp): 298 samples were isolated by Auto-Containment and 1 executed; however, when I uploaded that file to VirusTotal, no engines detected a threat. I ran some checks, and it appears the file is either legitimate, an incomplete malware sample (the type that needs to download a payload but fails to complete that step, even without CIS), or simply a corrupted/incomplete file.
Now, I'm just waiting to see if Loyiza will be kind enough to send me her new PoC/exploit so I can test it in a future livestream against the new CIS 2027
Livestream link:
(In pt-BR only. I don´t know if Youtube already made the automatic subs for this live)