- Oct 17, 2023
- 100
Based on the sections entropy check! file is possibly packed
Anti-vm present
you need to upload it here Comodo Valkyrie Customer Login | Advanced File Analysis System or at Xcitium verdict cloud@Nikola Milanovic fwiw, I downloaded what I think is a well known file, windows firewall control, logged into Valkyrie, I submitted sha256 and it said not a valid hash format (paraphrase) then I uploaded the file and Valkyrie computed the sha1 correctly but reported File Not Found. I do not have Xcitium installed (yet) but I understood that Valkyrie would run its analysis for would-be user of Valkyrie.
ok, yeah but, so I login on this page and I get "Invalid login credentials" Unclear (to me) why I would need to create a second account, or want to have two (2) Valkyrie accounts...you need to upload it here Comodo Valkyrie Customer Login | Advanced File Analysis System or at Xcitium verdict cloud
It is definitely more trouble than it’s worth. And I am not sure why static analysis needs to be performed in the cloud, I don’t see any data being displayed that is worth computing in the cloud. It could be performed locally as well. Where is the dynamic analysis?ok, yeah but, so I login on this page and I get "Invalid login credentials" Unclear (to me) why I would need to create a second account, or want to have two (2) Valkyrie accounts...
Not trying to sound intentionally negative here, but this is progressing toward more trouble that it is probably worth.
you need to create the second account because your other Valkyrie is Valkyrie verdict and the one i sent you its just Valkyrieok, yeah but, so I login on this page and I get "Invalid login credentials" Unclear (to me) why I would need to create a second account, or want to have two (2) Valkyrie accounts...
Not trying to sound intentionally negative here, but this is progressing toward more trouble that it is probably worth.
Because VirusScope uses Static and Dynamic Analysis thats whyIt is definitely more trouble than it’s worth. And I am not sure why static analysis needs to be performed in the cloud, I don’t see any data being displayed that is worth computing in the cloud. It could be performed locally as well. Where is the dynamic analysis?
Wasn’t VirusScope behavioural blocking or does it perform pre-execution analysis as well. And if VirusScope performs pre-execution analysis then what’s the point of Valkyrie which seems to be mainly static analysis as well?Because VirusScope uses Static and Dynamic Analysis thats why
Containment is sandbox so in the sandbox VirusScope does Static and Dynamic Behavioral Analysis and delivers the verdict to Valkyrie and to the userWasn’t VirusScope behavioural blocking or does it perform pre-execution analysis as well. And if VirusScope performs pre-execution analysis then what’s the point of Valkyrie which seems to be mainly static analysis as well?
It doesn’t sound like a very smart setup.Containment is sandbox so in the sandbox VirusScope does Static and Dynamic Behavioral Analysis and delivers the verdict to Valkyrie and to the user
it is smart setup for most of the usersIt doesn’t sound like a very smart set
This setup is being mentioned in the context of Harmony Endpoint by Check Point lately. It should be clear to users that it is in no way similar to Check Point/Crowd Strike/Palo Alto.it is smart setup for most of the users
and to mention that Valkyrie also has Dynamic AnalysisIt is definitely more trouble than it’s worth. And I am not sure why static analysis needs to be performed in the cloud, I don’t see any data being displayed that is worth computing in the cloud. It could be performed locally as well. Where is the dynamic analysis?
It doesn't necessarily have to run in the sandbox in order for VirusScope to kick in. You can change that in the settings.Containment is sandbox so in the sandbox VirusScope does Static and Dynamic Behavioral Analysis and delivers the verdict to Valkyrie and to the user
How does it fair with sandbox aware malware, and malware coded to jailbreak sandboxes. How does it handle out bound connection to C&C servers as it performed dynamic analysis. What is the criteria of dynamic analysis based on, which aspects does it analyze. How efficient/effective is this analysis is everything being addressed by the automation. What is the ratio of false positives and false negatives, these automated tools are only as good as the rules they are written with compared to manual dynamic analysis and reverse engineering of the malware.Containment is sandbox so in the sandbox VirusScope does Static and Dynamic Behavioral Analysis and delivers the verdict to Valkyrie and to the user
I only use containment and virus scope blades.The biggest value is the whitelist. Tbh. Cruel config with the open edr and Xcitium is best.
When locally sandboxed you won't need to worry about damage. You may also make rules to Deny traffic for contained items. Their cloud sandbox is prone to the save evasions as all others. From personal experience... I've submitted samples that tricked the comodo cloud sandbox. Check out some of my malware analysis post's for examples.How does it fair with sandbox aware malware, and malware coded to jailbreak sandboxes. How does it handle out bound connection to C&C servers as it performed dynamic analysis. What is the criteria of dynamic analysis based on, which aspects does it analyze. How efficient/effective is this analysis is everything being addressed by the automation. What is the ratio of false positives and false negatives, these automated tools are only as good as the rules they are written with compared to manual dynamic analysis and reverse engineering of the malware.
yes you can configure it to also monitor outside the sandboxIt doesn't necessarily have to run in the sandbox in order for VirusScope to kick in. You can change that in the settings.
would Xcitium by compatible with another anti-malware product? Also, are sandboxes items unable to work properly?I only use containment and virus scope blades.
Sandboxed items by Xcitium are analyzed by VirusScope(Static and Dynamic Analysis) but some applications dont work in the sandbox and just die because Xcitium doesnt allow an app to connect to the internet so there is no internet connection in the sandbox and yes its compatiblewould Xcitium by compatible with another anti-malware product? Also, are sandboxes items unable to work properly?
It works with alot of edrs. My clients using defender ATP with Containment Bladewould Xcitium by compatible with another anti-malware product? Also, are sandboxes items unable to work properly?