Cuckoo Install - Your Own Malware Sandbox!

Поделиться
HTML-код
  • Опубликовано: 4 авг 2024
  • Join me as we install Cuckoo. Your very own malware sandbox! Let's deploy a Host Intrusion Detection System and SIEM with free open source tools. Join me as we explore and learn together.
    GitHub: github.com/OpenSecureCo/Demos...
    Doc: cuckoo.sh/docs/installation/h...
    Discord Channel: / discord
    Check us out: www.opensecure.co/
    Interact with our demo: www.opensecure.co/demo
    Hire us: www.opensecure.co/contact-us
  • НаукаНаука

Комментарии • 72

  • @peterm.5912
    @peterm.5912 2 года назад +4

    This video made my day! My sandbox finally worked! I was banning my head trying to set it up with GUI. Headless VMs made it work with my limited compute resources.

  • @henrique8368
    @henrique8368 Месяц назад

    After some days trying to use this sandbox i found your tutorial, it solved my problems and is working great! Thanks a lot.

  • @mohammedshengheer3730
    @mohammedshengheer3730 2 года назад +3

    Great video, I was really looking for a video guiding me to step-by-step process of how to prepare cuckoo.
    I will try this next week and I hope that it works without any issue.
    Thank you for your efforts.

  • @bilalsec
    @bilalsec Год назад

    Thank you that helping me for creating environment dynamic analysis thanks again

  • @cristian-navarro-88
    @cristian-navarro-88 2 года назад +1

    great bro! thanks for your job!

  • @nikaimanns7045
    @nikaimanns7045 2 года назад

    Great video man !

  • @oceano8725
    @oceano8725 2 года назад

    Really thanks for all!

  • @eltoniferse8798
    @eltoniferse8798 6 месяцев назад

    tyvm for this guide

  • @meandmyRC99
    @meandmyRC99 2 года назад

    Awesome, thanks,

  • @alexandrohdez3982
    @alexandrohdez3982 Год назад

    Thank you 👏👏👏

  • @thomashope3110
    @thomashope3110 2 года назад

    The Vnet box stuff kind of goes over my head, do you need your original ubuntu vm running in a dmz environment?

  • @tshepisomotsoaledi6324
    @tshepisomotsoaledi6324 2 года назад +6

    Another great video. Would love to see cuckoo integration with both misp and cortex

  • @kabyg424
    @kabyg424 8 месяцев назад

    Great video. Can i set up a windows 7 vm with iso on vmware instead using virtual machine github part in your video ?

  • @santory666
    @santory666 2 года назад

    Do you know how I can delete snapshots if I want to install some additonal package to cloned image ? I have tried deleting Snapshots from VirtualBOX GUI or Run VBoxManage unregistervm | [--delete] and it works but VMs are still listed when running "vmcloak list vms" Do I have to delete snapshots using some vmcloak snapshot command ?

  • @valeriybaybekov
    @valeriybaybekov 2 года назад

    Hi! I have a problem, after creating win7 image: vmcloak init --verbose --win7x64 win7x64base --cpus 2 --ramsize 2048
    I got this loop error message with debug mode: DEBUG:vmcloak.vm:Running command: ['/usr/bin/VBoxManage', 'showvminfo', u'win7x64base', '--machinereadable']
    Can u help me? Im using Ubuntu same as you on the virtualbox. Im waited for 30 minutes and nothing happend.

  • @load7791
    @load7791 11 месяцев назад

    sudo apt-get install mongodb -y doesn't seem to work because that package has no valid installation candidate. Any alternatives?

  • @AkAk-jv7ig
    @AkAk-jv7ig 2 года назад

    thanks for the informative video :), i was thinking maybe we can do an automated analysis for email attachment i remember saw it somewhere online it was an awesome project.

    • @taylorwalton_socfortress
      @taylorwalton_socfortress  2 года назад +1

      Yes I actually have a similar video to that in the pipeline! Stay tuned and thanks for watching!

  • @DamikoMu
    @DamikoMu 2 года назад

    Thank you for this awesome guide! By the way: How can I automate the process of rebooting cuckoo after unwanted VM restart (power off and etc)?

    • @taylorwalton_socfortress
      @taylorwalton_socfortress  2 года назад

      You could create a bash script that runs the various cuckoo tools commands "rooter, cucko web, cuckoo, etc." and runs them as a background job

  • @RomanAArias-yy9rw
    @RomanAArias-yy9rw Год назад +1

    Amazing video, I was strugling to get cuckoo up and running (mostly because of the different versions referenced in the docos). Any good KB article what guides me to spin up a linux VM instance inside cuckoo to analyze Linux/ELF like malware? Thanks.

    • @jondo-vh8tx
      @jondo-vh8tx 9 месяцев назад

      how is the video amazing when you cant barely install the thing?

  • @cybersecurity-for-all
    @cybersecurity-for-all Год назад

    hello , i have this error after running cuckoo : Error checking for the latest Cuckoo version: ("bad handshake: Error([('SSL routines', 'tls_process_server_certificate', 'certificate verify failed')],)",)!

  • @jondo-vh8tx
    @jondo-vh8tx 9 месяцев назад

    update regarding the steup. it took me almost one week but its fully functional now. i must admit its a beautiful machine.

  • @GEORGECAR4
    @GEORGECAR4 2 года назад

    if i do the network routing for the internet like the video and have the network for the win7 vm set host adapter only. will it put other devices on my actual network at risk if i run wannacry inside cuckoo?
    great video yours is the best one Ive watch !

    • @taylorwalton_socfortress
      @taylorwalton_socfortress  2 года назад

      Hey George, it is my understanding that using the "dirty line" technique, the vm can only reach the internet, no other internal hosts: cuckoo.readthedocs.io/en/latest/installation/host/routing/. But please ensure to tread carefully! Thanks for watching

  • @theodoremr4878
    @theodoremr4878 2 года назад +1

    Really helpfull video!
    Something i would like ask is how to turn on virtualization inside ubuntu host? Thats the reason can't clone the win7x64base in 20:03...

    • @m_haritsah
      @m_haritsah Год назад

      mee too, need to fix this

  • @Xpinux
    @Xpinux Год назад

    i am getting an error for markupsafe -|> i am using ubuntu 16.04 with python2.7

  • @ozzykampha2776
    @ozzykampha2776 2 года назад +2

    Can you do one on CapeV2

  • @ehabalmasri8095
    @ehabalmasri8095 4 месяца назад

    Hello, thank you for your video. how can install cuckoo with python 3?

  • @ily455_e
    @ily455_e Год назад +1

    What are the versions used for mongodb and virtualbox. I tried mongodb version 4 and 5 with vbox v5.2 but there's a dependency conflict as mongodb uses libcurl4 and virtualbox uses libcurl3. I tried a couple of solutions online but none of it seemed to work.

    • @ily455_e
      @ily455_e Год назад +1

      If you had this problem use mongodb 3.6

  • @Alan-wd5uq
    @Alan-wd5uq 2 года назад

    Hello, can you help me?
    It tells me that python 2 is deprecated, so I can't use pip either.
    I have to use pip3 for everything or how can I continue? Thank you

    • @taylorwalton_socfortress
      @taylorwalton_socfortress  2 года назад

      As of now Cuckoo is not written for Python3...they say it is in the works but it has been a few years that they have been saying that so I am not sure if that is still on their roadmap. I would advise checking out CapeV2 which is a fork of Cuckoo and is a tool I am hoping to deploy soon! github.com/kevoreilly/CAPEv2

  • @RggD9
    @RggD9 3 месяца назад

    Can Iit analyze windows executable?

  • @CyberLogKing
    @CyberLogKing Год назад

    mkvirtualenv -p python2.7 cuckoo-test it gives me error mkvirtualenv command not found
    how to fix this

  • @ozzykampha2776
    @ozzykampha2776 2 года назад

    Can you do one on cuckoo 3?

  • @-sh2955
    @-sh2955 2 года назад

    Please make an installation video for Mac

  • @brave870307
    @brave870307 Год назад +1

    hello
    when i run
    sudo setcap cap_net_raw,cap_net_admin=eip /usr/sbin/tcpdump
    get this reply when
    Failed to set capabilities on file `/usr/sbin/tcpdump' (Invalid argument)
    The value of the capability argument is not permitted for a file. Or the file is not a regular (non-symlink) file
    I have tried all kinds of methods on the Internet and can't solve this problem
    Could you please help me?

  • @Ev3rnub
    @Ev3rnub 2 года назад

    I’m enjoying the content. I ran into an issue when attempting to install office. I can’t find the documentation for vmcloak flags/switches to provide the path to office.exe and or the flag/switch to specify the office key. Any help would be appreciated.

    • @taylorwalton_socfortress
      @taylorwalton_socfortress  2 года назад

      Hey Ev3rNub, you can use this command to install office "vmcloak install win7x64cuckoo office office.version=2007 office.isopath=/path/to/office2007.iso office.serialkey=XXXXX-XXXXX-XXXXX-XXXXX-XXXXX"
      You can grab the office2007 iso from here: archive.org/download/ms-office-2007/MS%20Office%202007.iso
      Thanks for watching!

    • @Ev3rnub
      @Ev3rnub 2 года назад

      @@taylorwalton_socfortress Thank you, I did see this, however I don't have an office 2k7 serial key, just a 2013 one from my laptop.

    • @taylorwalton_socfortress
      @taylorwalton_socfortress  2 года назад

      @@Ev3rnub You could use office 2013 as well just make sure you specific that version and the correct iso

    • @Ev3rnub
      @Ev3rnub 2 года назад

      @@taylorwalton_socfortress I have the executable for office2013, no ISO.

  • @user-tk7ep6bl7z
    @user-tk7ep6bl7z Год назад

    Any chance of getting installation video of cuckoo for latest python3. Not able to install yet all using these commands.

    • @edwardlenovo3240
      @edwardlenovo3240 Месяц назад

      the actual cuckoo project is abandoned and no longer maintained...sooo you aren't going to be getting anything anytime soon

  • @SoulJah876
    @SoulJah876 2 года назад +1

    I'm hitting a lot of errors with the commands as shown in the github link. Are they still correct? I'm on Ubuntu 21.10.

    • @taylorwalton_socfortress
      @taylorwalton_socfortress  2 года назад +2

      I haven't tested on Ubuntu 21.10. I deployed on Ubunut 20.04 in this video...what errors are you getting? Maybe you could try downloading what is missing?

    • @SoulJah876
      @SoulJah876 2 года назад +1

      @@taylorwalton_socfortress when I try to install m2crypto via sudo pip install M2Crypto, I get a wall of errors. If I try to proceed without that, then the installation for cuckoo itself also results in a wall of errors. I copied and pasted the commands to be certain, which were all successful up until that m2crypto attempt. I'm not sure where to begin re: finding root cause in the errors I received.

  • @suwandawanda4506
    @suwandawanda4506 Год назад

    why my cuckoo pendingfor anakyze?

  • @akash-fu6ts
    @akash-fu6ts 2 года назад

    can i use cuckoo with big .exe installers which is of 2gb or 30gb

    • @taylorwalton_socfortress
      @taylorwalton_socfortress  2 года назад

      Hey there, I’m not sure what the limit is on file size restrictions. Not sure if it is hard set directly within Cuckoo or if it only depends on resources available to your VM. Be worth a stress test :) let me know what you find out.
      Thanks for watching!

  • @NguyenThuTrangBDCAT
    @NguyenThuTrangBDCAT Год назад

    can you do on Cuckoo 3 please :(

  • @nicholaskorfer8257
    @nicholaskorfer8257 2 года назад +1

    The first time it works, but after a Reboot, I can't use it anymore. It would be nice if you also would make a video on how to set up cuckoo to autostart after reboot.

    • @mastersergant1287
      @mastersergant1287 Год назад +2

      run a systemctl enable command to startup the services upon reboot

    • @SusanPowers-wj2ow
      @SusanPowers-wj2ow Месяц назад

      @@mastersergant1287bro I can’t believe you were the first person to reply to this guy about the enable option for systemctl. Good looking out!
      Hope you all are playing with every Linux distro, it’s the easiest way to learn your way around the terminal and even powershell imo.
      Ctrl+A moves the cursor to the begging of a command,
      Ctrl+E moves the cursor to then end of a command.

  • @trishulsingh01
    @trishulsingh01 6 месяцев назад

    i am getting 404 for win7 iso

  • @KamiK4ze
    @KamiK4ze Год назад

    whaat its asking me a password for cuckoo during the bash script part - I thought we disabled the passwords

    • @KamiK4ze
      @KamiK4ze Год назад +1

      dude why is this so complicated - I keep running into more errors

  • @rishidev7150
    @rishidev7150 2 года назад

    In order to use the cuckoo web interface it is required to have mongodb up and running and enabled in cuckoo.please refer to our offocial documentation as well as the reporting.conf file.
    This is the error i get when I run the web interface.. Please let me know a solution

  • @jondo-vh8tx
    @jondo-vh8tx 9 месяцев назад

    has anyone seriousally been able to install this thing? i doubt it.

  • @andrewa3216
    @andrewa3216 Год назад +1

    Anyone know if there's just an OVA for this? Seems like a lot of boring stuff I have no interest in doing. I'd just like to try cuckoo out.

  • @jasonledesma9511
    @jasonledesma9511 Год назад

    please help. got an error when I run this command: vmcloak init --verbose --win7x64 win7x64base --cpus 2 --ramsize 2048
    It seems that it cannot create VM. see below:
    Could not create the medium storage unit '/home/.../VirtualBox VMs/HDNode1/HDNode1.vdi'. VDI: setting image size failed for '/home/.../VirtualBox VMs/HDNode1/HDNode1.vdi' (VERR_INVALID_PARAMETER).
    Result Code: VBOX_E_FILE_ERROR (0x80BB0004) Component: MediumWrap Interface: IMedium {4afe423b-43e0-e9d0-82e8-ceb307940dda}

  • @ekremozdemir99
    @ekremozdemir99 2 года назад

    Hi, I have used Ubuntu server 20.04.4 LTS... and couldt get over the following step.
    ekrem@ubuntu20:/opt$ mkvirtualenv -p python2.7 cuckoo-test
    mkvirtualenv: command not found