Skip to content

A Whitebox 2008 Proto-type for malware detection

License

Notifications You must be signed in to change notification settings

gitcollect/whitebox

 
 

Repository files navigation

Whitebox

Whitebox Proto-type

Released as open source by NCC Group Plc - http://www.nccgroup.com/

Developed by Ollie Whitehouse, ollie dot whitehouse at nccgroup dot com

http://www.github.com/nccgroup/whitebox

Released under AGPL see LICENSE for more information

(c) 2008 - 2013 Ollie Whitehouse
(c) 2013 NCC Group Plc

Retro release

This proto-type was originally designed a developed during Christmas 2008 / 2009 to show how a non signature based AV could reliably detect malicious code.

Documentation

See Whitebox/Documentation/Whitebox.pptx - https://github.com/nccgroup/whitebox/blob/master/Whitebox/Documentation/Whitebox.pptx?raw=true

Supported Platforms

It was designed to work with Windows XP back then (it uses the Sysinternal filemon and regmon drivers for some instrumentation).

Example Configuration

See Whitebox/Documentation/Config.Example.xml

About

A Whitebox 2008 Proto-type for malware detection

Resources

License

Stars

Watchers

Forks

Releases

No releases published

Packages

No packages published

Languages

  • HTML 83.0%
  • C 12.0%
  • C++ 4.5%
  • Other 0.5%