Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Cuckoo UM hooks protection #57

Open
wants to merge 1 commit into
base: master
Choose a base branch
from
Open

Cuckoo UM hooks protection #57

wants to merge 1 commit into from

Conversation

x9090
Copy link

@x9090 x9090 commented Dec 14, 2017

It's known that malware can easily tamper cuckoo's UM hooks, which in turn disable the Cuckoo's capability to monitor API calls, by restoring the API hooks to its original state. This UM protection is implemented such that it prevent the UM hooks being tampered and at the same time does not affect the sample's execution

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

1 participant