遇见数据集

Dorothy2

收藏
DataCite Commons2020-07-30 更新2025-04-09 收录
官方服务:

资源简介:

Dorothy2 is a framework created for suspicious binary analysis. Its main strengths are a very flexible modular environment, and an interactive investigation framework with a particular care of the network analysis. Additionally, it is able to recognise new spawned processes by comparing them with a previously created baseline. Static binary analysis and an improved system behaviour analysis will be shortly introduced in the next versions. Dorothy2 analyses binaries by the use of pre-configured analysis profiles. An analysis profile is composed by the following elements: - A certain sandbox OS type - A certain sandbox OS version - A certain sandbox OS language - A fixed analysis timeout (how long to wait before reverting the VM) - The number of screenshots requested (and the delay between them) - A list of the supported extensions, and how the guest OS should execute them

提供机构:
IMPACT
创建时间:
2019-09-10
二维码
社区交流群
二维码
科研交流群
商业服务