Perhaps a Malware Behavior Blocker\Heuristics Sub-Forum?

  • Thread starter Thread starter hjlbx
  • Start date Start date
Status
Not open for further replies.
H

hjlbx

Thread author
Hello,

I'm just thinking "out loud" here.

A Behavior Blocker\Heuristics Malware Hub sub-forum might be interesting.

Another sub-forum... right?

Members do a great job of reporting detection tests. However, very rarely does anyone report on how the security software responds if there is no signature detection.

Not too sure if it would work, but the behavioral\heuristic components that we all rely upon could certainly use scrutiny.

I admit there are potential problems... but generally the AVs will clearly indicate any behavior blocker\heuristics actions either in a classification or logs. So reporting actions should not be an issue.

When I test Emsi, if there is no signature detection, I will report how its Behavior Blocker responded in the Hub. If it's a different vendor I will report any heuristic "blocks."

In any case, just some thoughts.
 
  • Like
Reactions: Solarquest
Undetected samples are usually submitted by the Malware Hunters team within approx. 48 hours. @Malware1

I don't see why another sub-forum would be necessary, as the non-signature detected files can still be stated as Detected/Flagged by X proactive protection module. Accompanied by a screenshot, as per standard procedure for posting results.

Other than that, thanks for the suggestion. :D
 
  • Like
Reactions: MalwareT
Status
Not open for further replies.