New Update Introducing RxCloud CyberLab

🧾RxCloud CyberLab – Dashboard Changelog

Version: 0.0.3.5_RC_Stable


56D0chF.png


rtUJMaW.png


Z0ZWxko.png

🏅 Badge System (NEW)

RxCloud CyberLab now includes a brand-new Badge System to reward progression, activity, and good research behavior.

✅ First badges available:
  • First Boot — launch your first VM session
  • First Report — generate your first PDF report
  • Lab Regular — 10 completed sessions
  • Power User — 50 completed sessions
  • Sample Hunter — upload your first sample
  • IOC Collector — collect/extract IOCs
  • Bug Reporter — submit a bug report / feedback
  • Clean Researcher — good behavior, no abuse / no suspicious activity
  • RxCloud Pioneer — early adopter badge
  • Trusted Researcher — manual badge at first, granted by the admin

Earnable Badges:

bho8Bc3.png
jArlPPg.png
JMWZn9a.png
jAbfQk9.png
cnmVtTK.png
QF653H3.png
J76drPu.png
DyZG0IB.png
6ODgXKh.png
DFugxei.png




📝 Notes
  • This is the first step of the progression system — more badges and rewards will be added in future updates
 
🧾RxCloud CyberLab – Update Changelog

Dashboard version: 0.0.3.6_RC_Stable

📅Date:
2026-01-24
🛠Maintenance duration: 2h30



🖥️ Dashboard
  • Added a new VM Down indicator in the floating Lab VMs Status panel
  • Fixed a bug where a VM allocation status was not displayed in the floating Lab VMs Status panel

⚙️ RxCloud CoreLab Controller
  • Reinforced and improved VM orchestration by introducing a fallback system:
    • If a VM fails to start after 3 attempts, CoreLab Controller will mark it as Down
    • This status is then reported in the Dashboard floating Lab VMs Status panel
    • CoreLab Controller will automatically try to allocate another available VM of the same kind (PentestLab or ReverseLab)
    • The administrator will be notified when a VM is marked as down
 
🧾RxCloud CyberLab – Update Changelog

📅Date:
2026-01-29
🛠Maintenance duration: 9h30



🤖 RxLab Agent
  • Improved and refined Sysmon configuration for better event filtering
  • Enhanced low-level hook mechanisms for antivirus alert detection
  • Implemented a log size limitation rule within RxLab Agent and Sysmon:
    • Logs are now capped at 1 GB per slot to prevent excessive log growth

📄 RxLab Reports
  • Improved and refined PDF report structure, especially for IOC sections
  • Reduced noise generated by browser caches and Microsoft telemetry during sessions

⚙️ RxCloud CoreLab Controller
  • Improved queue management and VM high availability
  • Introduced a new VM self-repair feature for VMs that fail to start

🖥️ Guacamole RDP
  • Fixed a minor issue that could occasionally prevent users from connecting on the first attempt
  • Updated Guacamole and Debian Server packages
  • Applied latest security patches

🧬 ReverseLab VMs
  • Updated reverse engineering software stack
  • Updated third-party software (Java, Firefox, Notepad++)
  • Applied latest Microsoft security updates and Office updates
  • Cleaned and compacted VDI files (reduced VM boot time)

🧪 PentestLab VMs
  • Updated third-party software (Java, Firefox, Notepad++)
  • Applied latest Microsoft security updates and Office updates
  • Cleaned and compacted VDI files (reduced VM boot time)



📝 Notes
  • VM VDI files have been optimized to reduce startup latency and allow faster VM restoration
 
🧾RxCloud CyberLab – Dashboard Update Changelog

Version: 0.0.3.7_RC_Stable


ndE9JDI.png

📅Date: 2026-01-30
🛠Maintenance duration: 1h



🖥️ Dashboard UI
  • Visual polish improvements across the Dashboard
  • Added icons to multiple sections and to the floating Lab VMs Status panel for better readability and UX

🔐 Backend & API
  • Micro-adjustments on API endpoints
  • Additional backend security hardening

🤖 RxBot Assistant
  • Fixed a bug where RxBot did not display a clear message when a slot ended
  • Users are now properly notified when their session slot finishes
 
🧾RxCloud CyberLab – Update Changelog

📅Date:
2026-02-07
🛠Maintenance duration: 2h30



⚙️ RxCloud CoreLab Controller
  • Improved VM management and allocation logic
  • Minor code adjustments to prepare upcoming VM upscaling

🖥️ Guacamole RDP
  • Updated Debian packages

🛡️ pfSense Firewall
  • Improved filtering rules inside VM VLANs

🧬 ReverseLab VMs
  • Updated reverse engineering software stack
  • Updated third-party software
  • VM optimizations for better overall performance

🧪 PentestLab VMs
  • Updated third-party software
  • VM optimizations for better overall performance



📝 Notes
  • A big thank you to all of you — every day more users are joining the labs, helping improve the overall experience for everyone!
 
🛠RxCloud CyberLab – VM Recovery Update

🖥VM:
ReverseLab-1
✅Status: Restored / Operational



Incident summary
ReverseLab-1 experienced a startup failure following an automatic snapshot restore.
CoreLab Controller correctly detected the VM as down (state=poweroff) and marked it as unavailable.

Manual snapshot restoration was successfully performed.

Recovery details
  • Root cause: Snapshot restore glitch (VirtualBox side)
  • Detection: Automatic (CoreLab Controller)
  • Resolution: Manual snapshot recovery
  • Current status: ReverseLab-1 back online
Notes
  • 📝The monitoring pipeline for catching this instantly — infrastructure resilience working as expected.
 
  • Like
Reactions: harlan4096
🧾RxCloud CyberLab – Dashboard Update Changelog

Version: 0.0.3.8_RC_Stable


82MfagU.png


8ap9TBg.png

📅Date: 2026-02-11
🛠Maintenance duration: 1h30



🖥️ Dashboard UI
  • Enhanced Dashboard visuals with more detailed network and disk resource usage
  • Added real-time color-coded indicators:
    • 🟢 Green: Low load
    • 🟠 Orange: Moderate load
    • 🔴 Red: High load

🔐 Backend & API
  • Fixed an issue where agent telemetry and PDF reports were no longer generated due to hardened pfSense firewall rules
  • Improved and updated the sys_stats API for more detailed real-time network and disk load reporting
 
  • Like
Reactions: harlan4096
🧾RxCloud CyberLab – Update Changelog

📅Date:
2026-02-14
🛠Maintenance duration: 1h00



⚙️ RxCloud CoreLab Controller
  • Fixed an issue where a running VM crash during an active session did not trigger automatic migration:
    • Previously, the slot was marked as finished due to VM Down and users had to request a new slot manually
    • Now, the slot is returned to the queue and CoreLab Controller attempts automatic failover to another available VM of the same kind
    • Up to 3 migration attempts are performed before aborting and notifying the user of an error
  • Improved and reinforced CoreLab orchestration
  • Enhanced snapshot repair logic with up to 3 recovery attempts before abandoning

🖥️ Guacamole RDP
  • Fixed a backend buffer overflow issue causing RDP session instability, random disconnects, and lag



📝 Notes
  • Special thanks to @Shadowra for reporting and helping identify this issue — the Bug Reporter badge has been awarded!
 
🧾RxCloud CyberLab – Update Changelog

📅Date:
2026-02-20
🛠Maintenance duration: 3h30



🤖 RxLab Agent
  • Improved in-VM telemetry collection:
    • Now monitors and captures PowerShell, Java, Batch scripts (including arguments) to better intercept LOLBins-based malware
  • Enhanced AV event detection via low-level hooks with support for additional vendors:
    • ThreatDown
    • Cylance
    • CrowdStrike
    • SentinelOne
    • Deep Instinct
  • Improved hook reliability for existing vendors
  • Fixed a hook issue with Qihoo 360 (AV was detected but events were not properly hooked)
  • Refined telemetry rules to reduce noise

📄 RxLab Reports
  • Improved final PDF report structure
  • Reduced unnecessary logs such as agent and Sysmon configuration events

🧬 ReverseLab VMs
  • Updated reverse engineering tools and third-party software
  • New preloaded tool: Microsoft Visual Studio Code is now available by default
  • VM performance optimizations

🧪 PentestLab VMs
  • Updated third-party software
  • VM performance optimizations

🛡️ pfSense Firewall
  • Refined filtering rules across VM VLANs

🖥️ Guacamole RDP
  • Applied latest Debian package updates
  • Updated Guacamole packages
  • Production testing completed — all systems operational



📝 Notes
  • A new feature is currently in development: users will soon be able to request VM video recording and download the raw session footage at the end of their slot
 
🧾RxCloud CyberLab – Dashboard Update Changelog

📅 Date:
2026-03-01
🛠Maintenance duration: 45 minutes

Version: 0.0.3.9_RC_Stable



🖥️ Dashboard
  • Minor Dashboard adjustments and visual polish improvements
  • Refined VM state indicators in the floating Lab VMs Status panel for better clarity

🤖 RxBot Assistant
  • Fixed a minor bug affecting assistant behavior

🔐 Backend & API
  • Improved stability and security of the vm_pool.php API endpoint



📝 Notes
  • The new raw VM video recording feature is still under development
  • A big thank you to the community — RxCloud CyberLab is about to surpass the milestone of 50 users!
 
🧾RxCloud CyberLab – Update Changelog

📅Date:
2026-03-02
🛠Maintenance duration: 7h30



🤖 RxLab Agent
  • Improved low-level hook mechanism for more reliable AV vendor event capture
  • Refined Sysmon rules for enhanced telemetry collection

📄 RxLab Reports
  • Minor PDF structure adjustments for improved readability

⚙️ CoreLab Controller
  • Added new Session End functionality:
    • Users can now manually end a session from the Dashboard instead of waiting for the full 1-hour slot
    • When a session is ended:
      • The slot is marked as ending
      • CoreLab Controller instructs the VM agent to consolidate and send telemetry logs
      • The VM is restored and released automatically
      • The PDF report is generated without waiting for slot timeout



🖥️ RxCloud Dashboard – Version 0.0.4.0_RC_Stable

  • Added an End Session button below Join in the Current Session section
  • Fixed a minor RxBot Assistant bug (modal closing issue due to ID collision)
  • UX improvements with clearer and more readable icons
  • When ending a session:
    • A Toast notification confirms that the request has been received
    • VM status changes to Ending… in the floating Lab VMs Status panel
    • Once successfully completed, a final Toast confirms success
    • The generated PDF report becomes available in Last Public Report

IcVUTRP.png



🧬 ReverseLab VMs
  • Applied latest Microsoft security updates (KB patches)
  • Updated reverse engineering tool stack
  • Updated third-party software (Office Pack, Notepad++, Visual Studio Code, etc.)

🧪 PentestLab VMs
  • Applied latest Microsoft security updates (KB patches)
  • Updated third-party software (Office Pack, Notepad++, etc.)

🖥️ Guacamole RDP
  • Applied latest Debian package updates
  • Guacamole optimizations



📝 Notes
  • Raw VM video recording feature is still under development
 
📢 RxCloud CyberLab – Stable Release Incoming

After several months of development and iterative improvements,
RxCloud CyberLab is entering its next milestone.

The platform is preparing for the v0.0.4.1_STABLE release.

https://rxcloud.fr/

The stable era begins.

This upcoming release focuses on stability, telemetry improvements, infrastructure resilience, and overall lab experience.

Key highlights of the platform:

  • Live malware analysis labs directly in the browser
  • PentestLab and ReverseLab environments
  • Automated VM orchestration with CoreLab Controller
  • Telemetry collection via RxLab Agent + Sysmon
  • Automated PDF reports generation
  • Sandbox isolation through pfSense VLAN segmentation
  • Browser RDP access via Guacamole

The goal of RxCloud CyberLab is simple:
provide an accessible cyber range where researchers can safely analyze malware, experiment, and learn.

Recent updates have introduced:

  • Improved telemetry capture (including LOLBins detection)
  • Enhanced VM orchestration with auto-failover
  • Manual session ending with instant report generation
  • Dashboard UX improvements and real-time VM monitoring
  • Infrastructure hardening and performance optimizations

And more features are already in development.

Coming soon:

  • Raw VM session video recording
  • Additional telemetry improvements
  • Further VM infrastructure scaling

Thanks to everyone already testing the platform and providing feedback.

The project is evolving quickly thanks to the community.
 
Last edited:
  • Like
Reactions: harlan4096
🧾RxCloud CyberLab – Update Changelog

Version:
0.0.4.1_Stable
📅Date: 2026-03-10
🛠Maintenance duration: Several hours

New website refactor: RxCloud CyberLab Website



🖥️ RxCloud CyberLab Dashboard

FddlwuH.png

  • Graphical interface polishing
  • Improved stability across all backend APIs
  • RxCloud CyberLab officially enters Stable release stage

A huge thank you to the community for bug reports, testing, and improvement suggestions!



🤖 RxLab Agent

  • Reconfigured Sysmon rules to refine telemetry collection
  • Reduced noise in captured events

📄 RxLab Reports

  • Refined generated reports structure
  • Improved filtering of unnecessary telemetry elements



🧬 ReverseLab VMs

  • VM optimization and VDI compaction
  • VM reconfiguration:
    • Microsoft telemetry disabled to significantly reduce noise
    • Automatic updates of third-party software disabled to avoid resource usage and telemetry noise
  • Applied latest Microsoft security updates
  • Updated reverse engineering tool stack
  • Updated VirtualBox Guest Additions

🧪 PentestLab VMs

  • VM optimization and VDI compaction
  • VM reconfiguration:
    • Microsoft telemetry disabled to significantly reduce noise
    • Automatic updates of third-party software disabled
  • Applied latest Microsoft security updates
  • Updated VirtualBox Guest Additions
  • Updated third-party software



⚙️ RxCloud CoreLab Controller

  • Improved robustness of automatic VM orchestration:
    • VM allocation improvements
    • VM restoration stability improvements
    • Automatic fallback if a VM crashes during an active slot
    • Automatic migration to another VM
    • Slot auto-extension to compensate for interruption
  • Improved crash recovery and VM repair stability

🖥️ RxCloud Guacamole

  • Applied latest Debian package updates
  • Improved Guacamole stability

🛡️ RxCloud Firewall (pfSense)

  • Refined firewall rules
  • pfSense log compaction



📝 Notes

  • The VM session video recording feature is still under development and testing. No release date announced yet.
  • RxCloud CyberLab has now surpassed 50 registered users!
  • All RxCloud Pioneer badges have been awarded (first 50 users only).
  • More badges will be introduced in upcoming updates.
 
⚠️ Service Notice – VM Connection Issue

We are currently experiencing a temporary issue affecting connections to the CyberLab virtual machines.

As a result, some users may be unable to start or connect to PentestLab and ReverseLab environments.

The issue has been identified and remediation is currently in progress. We are restoring the affected virtual machine environments to ensure full stability.

We apologize for the inconvenience and appreciate your patience while the service is being restored.

Further updates will be provided if necessary.

PS :
I broke the system by messing with a crappy tweak tool lol. 🥲

Turns out playing with a random tweak tool at night was not my brightest idea. 😅

— RoxasDev
 
Last edited:
🟢 Service Update – RxCloud CyberLab

The infrastructure has now been fully restored and all virtual machines are coming back online. ✅

The issue was caused by an overly aggressive Windows tweak tool that modified several system policies and unexpectedly broke Remote Desktop access inside the lab VMs.

All affected environments have been restored from backup and normal service is being gradually resumed.

Thank you to everyone for your patience while the issue was being resolved.

Lesson learned: experimenting with random system tweak tools late at night is rarely a good idea 😅

— RoxasDev
 
🧾RxCloud CyberLab – Update Changelog

Version:
0.0.4.2_Stable
📅Date: 2026-03-13
🛠Maintenance duration: 1h30



🖥️ RxCloud CyberLab Dashboard

iQ14IiI.png


iwbIjAK.png


e0KX3xD.png
  • Improved graphical interface with a more premium visual rendering
  • Dashboard layout improved for small screens
  • Added scrollbars in the floating Lab VMs Status panel for better navigation on compact displays
  • The Lab VMs Status panel can now be freely moved by the user inside the Dashboard
  • Profile and Badge modals have been redesigned to improve visibility (previously too transparent)
  • Mouse cursor behavior has been unified across all RxCloud CyberLab pages (site, dashboard, login, register, etc.)
  • Dashboard is now fully optimized for smaller screen resolutions



🔗 RxCloud Guacamole
  • Definitive fix for the latency issue during first VM connection
  • Previously, the connection could sometimes fail because the VM was not fully initialized yet
 
🧾RxCloud CyberLab – Update Changelog

📅Date:
2026-03-22
🛠Maintenance duration: 2h30



🤖 RxLab Agent
  • Reduced telemetry noise
  • Improved low-level hook mechanisms
  • Enhanced Sysmon logging
  • Improved telemetry collection and transmission
  • Improved detection of EDR/XDR products



📄 RxLab Reports – Major Upgrade

New module integrated: RxNeural

Advanced scoring and IOC correlation engine.



🧠 Executive Summary (NEW)
  • Threat Level
  • Risk Score (0–100)
  • Classification
  • Confidence Level
  • Network Activity
  • Persistence
  • Privilege Escalation
  • Payload Dropped
  • Short Verdict (1 sentence)

⏱️ Timeline of Key Events (NEW)
  • Compact chronological view of critical events

🧬 MITRE ATT&CK Mapping (Simplified)
  • Technique ID
  • Name
  • Confidence level: Observed / Probable / Suspected
  • Short evidence



📊 Scoring & Analysis Improvements
  • New explainable and conservative Risk Score system
  • Standardized classification:
    • Clean
    • Low Risk
    • Suspicious
    • Malicious
    • Critical
  • Confidence levels:
    • Low
    • Medium
    • High

🌳 Process Tree Improvements
  • New hierarchical process tree view (parent/child relationships)
  • Visual highlighting of suspicious/active processes
  • Smart condensed mode for large datasets
  • Tabular view preserved for compatibility

🔇 Noise Reduction
  • New Filtered Noise Summary section
  • Prioritization of relevant processes
  • Grouping of low-signal repetitive processes
  • Raw data preserved via expert mode (detailed appendix)

🛡️ AV Detection Improvements (PentestLab)
  • Filtering of non-actionable AV artifacts (.json, .png, .jpg, .log, etc.)
  • Prioritization of executable/script targets (.exe, .bat, .ps1, .jar, etc.)
  • Added "AV filtered events count" metric in summary



🎨 PDF Design & UX Overhaul
  • Modernized visual hierarchy (titles, badges, sections)
  • Improved table readability (spacing, wrapping, zebra style)
  • Enhanced header/footer (premium SaaS look)
  • Optimized margins and layout spacing
  • Improved pagination to avoid content splitting



⚙️ Technical Refactor
  • Clear separation between computation, orchestration, and rendering layers
  • Centralized style/layout helpers
  • Prepared for future extensions:
    • Advanced Executive Summary
    • Evolving Risk Score system
    • Extended Timeline
    • Expanded MITRE mapping
    • Client / Expert modes
  • Full backward compatibility maintained

🧬 MITRE ATT&CK Coverage
  • T1059 — Command and Scripting Interpreter
  • T1547.001 — Registry Run Keys / Startup Folder
  • T1112 — Modify Registry
  • T1105 — Ingress Tool Transfer
  • T1204.002 — User Execution: Malicious File
  • T1071.001 — Web Protocols
  • T1055 — Process Injection



🧬 ReverseLab VMs
  • Minor VM optimizations

🧪 PentestLab VMs
  • Minor VM optimizations

🖥️ RxCloud Guacamole
  • Applied latest Debian package updates



📝 Notes
  • VM session video recording feature is progressing well and under active development
 
🧾RxCloud CyberLab – Dashboard Update Changelog

Version: 0.0.4.4_Stable


xWion6h.png

📅Date: 2026-03-24
🛠Maintenance duration: 2h30



🖥️ Dashboard Improvements
  • Improved overall user interface and Dashboard ergonomics
  • Merged several sections for better coherence and usability
  • Reworked Server Health section:
    • Enhanced design
    • Improved visibility of server load metrics

🤖 RxBot Assistant
  • Improved layout and presentation to align with the updated Dashboard structure
  • Adapted to merged sections for better user guidance

📦 Sample Upload
  • Improved upload stability
  • Enhanced handling of large ZIP files (>256 MB)
 
🧾RxCloud CyberLab – Update Changelog

Version:
0.0.4.5_Stable
📅Date: 2026-03-26
🛠Maintenance duration: 5h30



🖥️ RxCloud CyberLab Dashboard

FeQoQCW.png

➤ Added
  • Structured JSON export automatically generated alongside each PDF report (.json sidecar)
  • New My Submissions button in the Dashboard
  • New My Submissions modal with user upload history
  • New secured API endpoint: /api/my_submissions.php (strict session-based user_id filtering)
  • Sample download from modal with 90-day retention policy

➤ Changed
  • Reports are now fully private per user (segregated by user_id)
  • Report pipeline now properly transports session metadata (user_id, qid, slot_id)
  • reports.php now supports PDF + JSON (listing, viewing, secure download)
  • Dashboard section updated:
    • View PDF
    • View JSON
    • Download JSON

➤ Security
  • Report access strictly scoped to authenticated user
  • Strengthened anti-path traversal protections
  • Direct web access to report files blocked (API-only access)
  • Ownership validation enforced for all submission downloads

➤ Fixed
  • Fixed encoding issues (mojibake)
  • Improved UI/JS stability for modals and buttons



🤖 RxLab Agent
  • Reduced telemetry noise
  • Improved low-level hooks for AV vendors
  • Optimized CPU usage during VM monitoring



📄 RxLab Reports – Major Evolution

➤ Architecture

  • Refactored PDF generator into modular system (computation / rendering / styling)

➤ Process Analysis
  • New hierarchical Process Tree view (with tabular fallback)
  • Behavior-based scoring for Top Analyst-Relevant Processes
  • Process classification:
    • SYSTEM_PROCESS
    • LEGITIMATE_APP
    • USER_PROCESS
    • SUSPICIOUS
    • MALICIOUS

➤ Timeline & Data Processing
  • Timeline deduplication and intelligent grouping (e.g., burst file events)

➤ PDF UX Redesign
  • Modernized layout (spacing, hierarchy, badges)
  • Print-friendly rendering
  • Page 1 optimized for 5-second readability:
    • Single title
    • Executive Summary
    • Risk Score
    • Verdict
    • Key Metrics

➤ Security & Detection Hardening
  • Improved persistence detection (strong signals only: Run/RunOnce, services, tasks, etc.)
  • Detection levels:
    • Not Detected
    • Weak Signal
    • Suspected
    • Confirmed
  • Hardened MITRE mapping:
    • Displayed only with explicit evidence
    • Confidence per TTP
    • Reduced false positives
    • Weak Signal hidden by default

➤ Fixed
  • Reduced false positives on legitimate processes (svchost, browsers, known apps)
  • Improved wrapping of long paths/logs:
    • Smart splitting
    • Indented continuation lines
    • Better table readability

➤ Compatibility
  • No raw data removed
  • Compatible with existing FPDF/iTextSharp pipeline
  • Expert mode fully preserved



⚙️ CoreLab Controller
  • Improved VM orchestration stability
  • Enhanced VM down detection
  • Slots now tagged with user_id for private telemetry and report generation



🧬 ReverseLab VMs
  • Updated reverse engineering tool stack
  • VDI compaction

🧪 PentestLab VMs
  • VDI compaction



📝 Notes
  • Next major update will focus on:
    • Raw VM session video recording
    • VM modifications to evade VirtualBox detection by malware
 
🧾RxCloud CyberLab – Update Changelog

📅Date:
2026-04-02
🛠Maintenance duration: 3h30




🤖 RxLab Agent – Core Detection Engine (Major Upgrade)

➤ Multi-layer Detection Engine

  • Introduced a multi-layer detection architecture
  • Added Fusion Engine with global scoring (0–100), classification, and confidence
  • Cross-layer correlation (corroboration bonuses) + legitimate context penalties to reduce false positives
  • Structured logging in core.log (layer_name, status, score_delta, confidence, evidence, raw_metadata)

➤ New Defensive Layers
  • Enhanced native telemetry (process, lineage, files, registry, DNS/NetConnect)
  • Integrated local heuristics inspired by XyWall (defensive, non-blocking mode)
  • Added Startup Guard (Run/RunOnce, Winlogon, Tasks, Services, IFEO, WMI)
  • Added Registry Defense with categorized sensitive zones + deduplication
  • Added targeted Memory Scan (explicit signals, performance-controlled)
  • Added VirusTotal hash lookup layer (states: unavailable / unknown / cleanish / suspicious / malicious)
  • Integrated YARA (file + memory) as signal enrichment

➤ YARA Engine
  • Supported rulesets by categories:
    • malware_family
    • packer_obfuscation
    • loader_dropper
    • suspicious_behavior_markers
  • Weighted YARA scoring (rule/category weights, score cap, severity levels)
  • YARA whitelist/exclusions to reduce noise
  • Automatic starter rules deployment on agent bootstrap
  • Automatic extraction/sync of yara64.exe to C:\RxLab\tools\
  • Auto-update of yara64.exe via SHA-256 validation

➤ False Positive Reduction
  • Persistence detection now based only on strong evidence
  • Improved process classification (system / legit / user / suspicious / malicious)
  • Refactored "Top Analyst-Relevant Processes" ranking (signal-based, not volume-based)
  • Timeline deduplication and intelligent grouping
  • Stricter MITRE mapping (explicit evidence required)
  • Internal tooling noise filtering (hidden from analyst view)

➤ Agent / Pipeline Architecture
  • Agent is now the single source of truth for scoring and correlation
  • RxLab Reports moved to consume-only logic
  • Enriched artifacts exported directly from the agent (JSON + PDF pipeline)




📄 RxLab Reports

  • Enhanced and versionable JSON schema (executive_summary, risk_scoring, layer_results, evidence, etc.)
  • Modernized PDF design with improved hierarchy and readability
  • Strengthened sections:
    • Executive Summary
    • Risk Score & Verdict
    • Layered Detection Summary
    • Corroborating Evidence
    • Reputation & Rule Matches
    • Timeline of Key Events
    • Simplified MITRE ATT&CK
    • Final Analyst Conclusion
  • Added AV filtered events counter in summary
  • Improved layout to avoid empty zones and improve readability




⚙️ RxCloud CoreLab Controller
  • Improved VM down detection and fallback mechanisms
  • Enhanced handling of powered-off VMs during active slots:
    • Attempts to restart VM in current state
    • If unsuccessful → fallback and migration to another available VM

🖥️ RxCloud Guacamole
  • Applied latest Debian package updates




📝 Notes
  • This update focuses heavily on improving in-VM telemetry and malware analysis quality
  • VM raw video recording feature is still under development (ongoing optimization for CPU usage during encoding)
  • Ongoing work to reduce VirtualBox detection by malware
 

You may also like...