Today I have spoken with Florian and his girlfriend to discuss a roadmap to a "Excubits Malware Mitigation", this is the idea
Release 1: Only bouncer and MZwritescanner
- Adopt MZwriteScanner
- Add "parent process' feature (like parent process option of Bouncer)
- Add persistent block option (with configurable number of days
- Combine existing drivers into one new driver
- Develop GUI for configuration program which sets options in ini-files (so driver still does not have user mode access), this could be done by other developer.
Release 2: Add PumperNickel and Memprotect
- Add optional [Extensions] section to define to which extension read-write protection is provided (this would make writing rules easier)
- Rewrite configuration program (Florian wants final version to be coded by himself).
We agreed on setting up a community of trused testers at Wilders and MalwareTips and also on pricing (12 euro's for zero config with 3 euro for updates of ini-files and functionality.
Protection of release 1 is driveby infections and mailscam, release 2 adds exploit protection of often attacked vulnerable Medium IL processes and guarded programs and ransomware protection for Windows libraries (when user ads a folder to library through normal Windows functionality the restart option of tray-app should read Windows libraries and add them to protected files).
The above extra features would also be added (as option) to the existing drivers.
In january we will have contact again about implementation timeline/planning.
Regards Kees