Author Topic: JoeBox new release .  (Read 5911 times)

0 Members and 1 Guest are viewing this topic.

March 09, 2009, 12:04:32 am
Read 5911 times

B_H

  • Special Members
  • Full Member

  • Offline
  • *

  • 49
Quote
Joebox 1.3.0 (released 07.03.2009)

- Changed behaviour format from xml to easy parsable csv
- Handle data is extracted seperatly, improves integrity
- Added possiblity to hook gui function (for instance NtUserSetWindowsHookEx)
- Number of hooked system calls increased from 15 to 166 :)
- All parameters are extracted
- Parameter data are hashed, leads to quick comparison possibilites
- Added thread data to calls
- Added paremeter meaning data (for instance FILEACCESSMASK ULONG IN 1)
- Added new parameter to hooking config to influence side channel detection
- Added an anti unhook techniques
- Improved side channel (code injection) detection
- Improved exception handling in kernelmode
- Reimplemented the whole abstraction tool
- Abstraction tool is now platfrom independ
- Added mutant behaviour data to report
- Added open process/threads behaviour data to report
- Added possiblity to change static driver settings
- Added antivirus labeling
- Created a portable joebox version
- Portable version is able to analyse automatically exe,pif,cmd,bat,scr,com,pdf,html,msi,url,cab files
- Improved robustness of client-server communication by adding finate state machines
- Added a simple ping-pong protocol for checking analysis machine status
- Changed data transfer mechanism from ftp to samba
- Fixed various performance problems (extraction and abstraction)
- Fixed various deadlock problems
- Added various configuration settings
- Changed complete architecture from monolitic to controller based
- Improved the whole design
- Removed restore solution deep freeze
- Added pxe imaging solution fog
- Developped a secure ring0 hashmap
- Developped a secure ring0 linkedlist
- Reimplement whole diff tool
- Improved diff tool performance

some good options added .

March 09, 2009, 10:39:50 am
Reply #1

DiFor

  • Jr. Member

  • Offline
  • **

  • 19

March 09, 2009, 10:50:09 am
Reply #2

SysAdMini

  • Administrator
  • Hero Member

  • Offline
  • *****

  • 3335
what is it?

JoeBox is an online analysis service like ThreatExpert or Anubis.
Ruining the bad guy's day

March 09, 2009, 09:04:25 pm
Reply #3

DiFor

  • Jr. Member

  • Offline
  • **

  • 19

December 29, 2009, 08:20:46 am
Reply #4

SysAdMini

  • Administrator
  • Hero Member

  • Offline
  • *****

  • 3335
Joebox is now online again after a downtime of three months.

http://joebox.org/news.php
Ruining the bad guy's day