Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Package proposal: pafish.vm #173

Open
seanthegeek opened this issue Dec 7, 2022 · 5 comments
Open

Package proposal: pafish.vm #173

seanthegeek opened this issue Dec 7, 2022 · 5 comments
Labels
🌀 FLARE-VM A package or feature to be used by FLARE-VM ❔ discussion Further discussion is needed 🆕 package New package request/idea/PR

Comments

@seanthegeek
Copy link

Package Name

pafish

Tool Name

pafish

Package type

ZIP_EXE

Tool's version number

0.6

Category

Utilities

Tool's authors

Alberto Ortega, Others

Tool's description

Pafish is a testing tool that uses different techniques to detect virtual machines and malware analysis environments in the same way that malware families do

Download URL

https://github.com/a0rtega/pafish/releases/download/v0.6/pafish64.exe

Download SHA256 Hash

ff24b9da6cddd77f8c19169134eb054130567825eee1008b5a32244e1028e76f

Why is this tool a good addition?

Pafish is a testing tool that uses different techniques to detect virtual machines and malware analysis environments in the same way that malware families do.

@seanthegeek seanthegeek added the 🆕 package New package request/idea/PR label Dec 7, 2022
@seanthegeek
Copy link
Author

Note: Windows Defender and some other AVs falsely flag this EXE as malware, because it does many of the same VM/sandbox checks that malware does.

@doomedraven
Copy link

pafish is ultra dead, al-khaser is way much better for VM detection https://github.com/LordNoteworthy/al-khaser

@mr-tz
Copy link
Contributor

mr-tz commented Jan 2, 2023

al-khaser does not provide compiled binaries, otherwise, I'd vote to add it instead of pafish.

@Ana06 Ana06 added the 🌀 FLARE-VM A package or feature to be used by FLARE-VM label Oct 6, 2023
@Ana06
Copy link
Member

Ana06 commented Jul 17, 2024

It seems there is a build workflow, but the result is only uploaded as artifact (which means it is only kept for a short period of time). It should be easy though to convert it into a release workflow. @mandiant/flare-vm do you think this is a useful tool that should be added to FLARE-VM?

@Ana06 Ana06 added the ❔ discussion Further discussion is needed label Jul 17, 2024
@stevemk14ebr
Copy link
Contributor

stevemk14ebr commented Jul 17, 2024

I do not think al-khaser or pafish make sense in flare-vm. They are useful if you are writing anti-anti-vm or anti-anti-dbg tooling but there is no situation I can think of where you'd run one of these tools to better understand a malware sample. Hardening a VM is a one time thing not a recurring need for one of these tools.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
🌀 FLARE-VM A package or feature to be used by FLARE-VM ❔ discussion Further discussion is needed 🆕 package New package request/idea/PR
Projects
None yet
Development

No branches or pull requests

5 participants