Perhaps a Malware Behavior Blocker\Heuristics Sub-Forum?

Status
Not open for further replies.
H

hjlbx

Thread author
Hello,

I'm just thinking "out loud" here.

A Behavior Blocker\Heuristics Malware Hub sub-forum might be interesting.

Another sub-forum... right?

Members do a great job of reporting detection tests. However, very rarely does anyone report on how the security software responds if there is no signature detection.

Not too sure if it would work, but the behavioral\heuristic components that we all rely upon could certainly use scrutiny.

I admit there are potential problems... but generally the AVs will clearly indicate any behavior blocker\heuristics actions either in a classification or logs. So reporting actions should not be an issue.

When I test Emsi, if there is no signature detection, I will report how its Behavior Blocker responded in the Hub. If it's a different vendor I will report any heuristic "blocks."

In any case, just some thoughts.
 
  • Like
Reactions: Solarquest

Ink

Administrator
Verified
Staff Member
Well-known
Jan 8, 2011
22,361
Undetected samples are usually submitted by the Malware Hunters team within approx. 48 hours. @Malware1

I don't see why another sub-forum would be necessary, as the non-signature detected files can still be stated as Detected/Flagged by X proactive protection module. Accompanied by a screenshot, as per standard procedure for posting results.

Other than that, thanks for the suggestion. :D
 
  • Like
Reactions: MalwareT
Status
Not open for further replies.

About us

  • MalwareTips is a community-driven platform providing the latest information and resources on malware and cyber threats. Our team of experienced professionals and passionate volunteers work to keep the internet safe and secure. We provide accurate, up-to-date information and strive to build a strong and supportive community dedicated to cybersecurity.

User Menu

Follow us

Follow us on Facebook or Twitter to know first about the latest cybersecurity incidents and malware threats.

Top