- Notifications
You must be signed in to change notification settings - Fork258
DRAKVUF Black-box Binary Analysis
License
Unknown, Unknown licenses found
Licenses found
tklengyel/drakvuf
Folders and files
Name | Name | Last commit message | Last commit date | |
---|---|---|---|---|
Repository files navigation
DRAKVUF is a virtualization based agentless black-box binary analysis system. DRAKVUFallows for in-depth execution tracing of arbitrary binaries (including operatingsystems), all without having to install any special software within the virtual machineused for analysis.
DRAKVUF uses hardware virtualization extensions found in Intel CPUs. You will need anIntel CPU with virtualization support (VT-x) and with Extended Page Tables (EPT). DRAKVUFis not going to work on any other CPUs (such as AMD) or on Intel CPUs without therequired virtualization extensions.
DRAKVUF currently supports:
- Windows 7 - 8, both 32 and 64-bit
- Windows 10 64-bit
- Linux 2.6.x - 6.x, both 32-bit and 64-bit
You can find pre-built Debian packages of the latest DRAKVUF builds athttps://github.com/tklengyel/drakvuf-builds/releases
DRAKVUF provides a perfect platform for stealthy malware analysis as its footprint isnearly undectebable from the malware's perspective. While DRAKVUF has been mainlydeveloped with malware analysis in mind, it is certainly not limited to that task as itcan be used to monitor the execution of anything that executes within a VM, includingfirmware, OS kernels and user-space processes.
If you would like a full-featured DRAKVUF GUI to setup as automated analysis sandbox, check out theDRAKVUF Sandbox project.
Installation steps can be found on the project website:https://drakvuf.com
About
DRAKVUF Black-box Binary Analysis