以下是該 processing.conf 設定檔中各項處理模組(Processing Modules)的詳細功能說明。這些模組負責在沙盒動態執行完畢後,解析並結構化收集到的原始數據。
anomaly)、行程樹關聯 (processtree) 以及行為摘要 (summary)。支援記憶體加速 (ram_boost) 與迴圈偵測 (loop_detection) 以優化大型日誌處理效能。dropped) 以及行程記憶體傾印 (procdump),並支援正則表達式特徵替換與 PE 檔快取。strace 工具收集 Linux 環境下的系統呼叫 (System Calls) 與核心事件。ahash)比對分析過程中的螢幕截圖,自動刪除畫面重複的圖片以節省儲存空間。dnswhitelist)、處理程序網路映射 (process_map),以及結合 MaxMind/IPInfo 進行 GeoIP 國家地理位置查詢。minchars)。skip_number),防止勒索軟體加密大量檔案導致沙盒資源耗盡。# Enable or disable the available processing modules [on/off].
# If you add a custom processing module to your Cuckoo setup, you have to add
# a dedicated entry in this file, or it won't be executed.
# You can also add additional options under the section of your module and
# they will be available in your Python class.
# Community
# exclude files that doesn't match safe extension and ignore their files from processing inside of other modules like CAPE.py
[antiransomware]
enabled = no
# ignore all files with extension found more than X
skip_number = 30
# Community
[curtain]
enabled = no
# Community
[sysmon]
enabled = no
[analysisinfo]
enabled = yes
# Community
[decompression]
enabled = no
[dumptls]
enabled = no
[amsi_etw]
enabled = no
[behavior]
enabled = yes
# Toggle specific modules within the BehaviorAnalysis class
anomaly = yes
processtree = yes
summary = yes
enhanced = yes
encryptedbuffers = yes
# Should the server use a compressed version of behavioural logs? This helps
# in saving space in Mongo, accelerates searchs and reduce the size of the
# final JSON report.
loop_detection = no
# The number of calls per process to process. 0 switches the limit off.
# 10000 api calls should be processed in less than 2 minutes
analysis_call_limit = 0
# Use ram to boost processing speed. You will need more than 20GB of RAM for this feature.
# Please read "performance" section in the documentation.
ram_boost = no
# https://capev2.readthedocs.io/en/latest/usage/patterns_replacement.html
replace_patterns = no
file_activities = no
# Get network details from behavior
network_map = no
# process behavior files in ram to speedup processing a little bit?
ram_mmap = no
[tracee]
enabled = no
[strace]
enabled = no
# Toggle specific modules within the StraceAnalysis class
processtree = no
# Platform specific
platform = linux
update_file_descriptors = yes
[debug]
enabled = yes
# Amount of text (bytes)
buffer = 0
[detections]
enabled = yes
# Signatures
behavior = yes
yara = yes
suricata = yes
virustotal = no
clamav = no
# ... but this mechanism may still be switched on
[procmemory]
enabled = yes
strings = yes
[procmon]
enabled = no
[memory]
enabled = no
[usage]
enabled = no
[network]
enabled = yes
sort_pcap = no
# Which capture to analyze when decryptpcap produced additional outputs:
# auto | original | mixed | decrypted
pcapsrc = auto
# Enable mapping of network events to specific processes using behavioral analysis data
process_map = no
# Adds network connections seen in behavior but not in PCAP. Requires process_map = yes
merge_behavior_map = no
# DNS whitelisting to ignore domains/IPs configured in network.py
dnswhitelist = yes
# additional entries
dnswhitelist_file = extra/whitelist_domains.txt
ipwhitelist = yes
ipwhitelist_file = extra/whitelist_ips.txt
network_passlist = no
network_passlist_file = extra/whitelist_network.txt
# Requires geoip2 and maxmind database
country_lookup = no
# Register and download for free from
# https://www.maxmind.com/ or https://ipinfo.io/
# For maxmind use: GeoLite2 Country
# For ipinfo use: Free IP to Country + IP to ASN
maxmind_database = data/GeoLite2-Country.mmdb
[decryptpcap]
enabled = no
# Path to GoGoRoboCap binary (relative to CUCKOO_ROOT or absolute)
gogorobocap = data/gogorobocap/gogorobocap-linux-amd64
# Decryption source: auto (default), pcap_with_keylog, or sslproxy_synth_pcap
# auto: uses sslproxy synthetic pcap when available, falls back to keylog decryption
pcapsrc = auto
[pcapng]
enabled = no
[url_analysis]
enabled = yes
# Enable a WHOIS lookup for the target domain of a URL analyses
whois = yes
[strings]
enabled = yes
on_demand = no
nullterminated_only = no
minchars = 5
# Community
[trid]
# Specify the path to the trid binary to use for static analysis.
enabled = no
identifier = data/trid/trid
definitions = data/trid/triddefs.trd
[die]
# Detect it Easy
enabled = no
binary = /usr/bin/diec
[magika]
# Google Magika - deep-learning content type identification.
# https://github.com/google/magika
# Install: poetry run pip install -U magika
# Main benfit is classification of text file types i.e. PowerShell, ini files etc.
enabled = no
# Optional path to a custom/pinned model directory. Empty = use the model
# shipped with the installed magika package.
model_dir =
# high_confidence (default, most conservative) | medium_confidence | best_guess
prediction_mode = high_confidence
# Display-only: results scoring below this are still recorded and shown, just
# flagged low_confidence so a weak prediction isn't read as a confident one.
min_score = 0.5
# Skip files larger than this (MB). 0 = no limit. Magika only reads the head,
# middle and tail of a file, so this is cheap to raise.
max_file_size = 100
[virustotal]
enabled = yes
on_demand = no
timeout = 60
# remove empty detections
remove_empty = yes
# Add your VirusTotal API key here. The default API key, kindly provided
# by the VirusTotal team, should enable you with a sufficient throughput
# and while being shared with all our users, it shouldn't affect your use.
key = a0283a2c3d55728300d064874239b5346fb991317e8449fe43c902879d758088
do_file_lookup = yes
do_url_lookup = yes
# Use cached results from MongoDB if available
cache_default = no
cache_static = no
cache_file = no
cache_dropped = no
cache_cape = no
cache_procdump = no
urlscrub = (^http:\/\/serw\.clicksor\.com\/redir\.php\?url=|&InjectedParam=.+$)
# Since Suricata 8, socket mode is deprecated.
[suricata]
enabled = no
runmode = cli
# Which capture to analyze when decryptpcap produced additional outputs:
# auto | original | mixed | decrypted
pcapsrc = auto
# Outputfiles
# if evelog is specified, it will be used instead of the per-protocol log files
evelog = eve.json
# per-protocol log files
#
#alertlog = alert.json
#httplog = http.json
#tlslog = tls.json
#sshlog = ssh.json
#dnslog = dns.json
fileslog = files-json.log
filesdir = files
# Amount of text to carve from plaintext files (bytes)
buffer = 8192
#Used for creating an archive of extracted files
7zbin = data/7zz
zippass = infected
# Runmode "cli" options
bin = /usr/bin/suricata
conf = /etc/suricata/suricata.yaml
# Runmode "socket" Options. Deprecated since Suricata 8.
socket_file = /tmp/suricata-command.socket
# Community
[cif]
enabled = no
# url of CIF server
url = https://your-cif-server.com/api
# CIF API key
key = your-api-key-here
# time to wait for server to respond, in seconds
timeout = 60
# minimum confidence level of returned results:
# 25=not confident, 50=automated, 75=somewhat confident, 85=very confident, 95=certain
# defaults to 85
confidence = 85
# don't log queries by default, set to 'no' to log queries
nolog = yes
# max number of results per query
per_lookup_limit = 20
# max number of queries per analysis
per_analysis_limit = 200
[CAPE]
enabled = yes
# Ex targetinfo standalone module
targetinfo = yes
# Ex dropped standalone module
dropped = yes
# Ex procdump standalone module
procdump = yes
# Amount of text to carve from plaintext files (bytes)
buffer = 8192
# Process files not bigger than value below in Mb. We saw that after 90Mb it has biggest delay
max_file_size = 90
# Scan for UserDB.TXT signature matches
userdb_signature = no
# https://capev2.readthedocs.io/en/latest/usage/patterns_replacement.html
replace_patterns = no
# Use file cache to speed up processing by looking up already processed files in MongoDB
file_cache = no
# Store pefile objects for later usage? useful if you doing something in signatures/reporting
pefile_store = no
[network_etw]
enabled = no
# Deduplicate screenshots - You need to install dependency ImageHash>=4.3.1
[deduplication]
#
# Available hashs functions:
# ahash: Average hash
# phash: Perceptual hash
# dhash: Difference hash
# whash-haar: Haar wavelet hash
# whash-db4: Daubechies wavelet hash
enabled = no
hashmethod = ahash
# Community
[vba2graph]
# Mac - brew install graphviz
# Ubuntu - sudo apt-get install graphviz
# Arch - sudo pacman -S graphviz+
# sudo poetry run pip install networkx>=2.1 graphviz>=0.8.4 pydot>=1.2.4
enabled = yes
on_demand = yes
# ja3 finger print db with descriptions
# https://github.com/trisulnsm/trisul-scripts/blob/master/lua/frontend_scripts/reassembly/ja3/prints/ja3fingerprint.json
[ja3]
ja3_path = data/ja3/ja3fingerprint.json
[maliciousmacrobot]
# https://maliciousmacrobot.readthedocs.io
# Install mmbot
# sudo poetry run pip install mmbot
# Create/Set required paths
# Populate benign_path and malicious_path with appropriate macro maldocs (try the tests/samples in the github)
# https://github.com/egaus/MaliciousMacroBot/tree/master/tests/samples
# Create modeldata.pickle with your maldocs (this does not append to the model, it overwrites it)
#
# mmb = MaliciousMacroBot(benign_path, malicious_path, model_path, retain_sample_contents=False)
# result = mmb.mmb_init_model(modelRebuild=True)
#
# Copy your model file and vocab.txt to your model_path
enabled = no
benign_path = /opt/cuckoo/data/mmbot/benign
malicious_path = /opt/cuckoo/data/mmbot/malicious
model_path = /opt/cuckoo/data/mmbot/model
# Community
[xlsdeobf]
# poetry run pip install git+https://github.com/DissectMalware/XLMMacroDeobfuscator.git
enabled = no
on_demand = no
# Community
[boxjs]
enabled = no
timeout = 60
url = http://your_super_box_js:9000
# Community
# Extractors
[mwcp]
enabled = yes
modules_path = modules/processing/parsers/mwcp/
# Community
[ratdecoders]
enabled = yes
modules_path = modules/processing/parsers/RATDecoders/
# Community
[malduck]
enabled = yes
modules_path = modules/processing/parsers/malduck/
# installed from PYPI
[CAPE_extractors]
enabled = yes
# Must ends with /
modules_path = custom/parsers/
# Config parsers all/core/community
parsers = all
# list of comma separated parsers. Ex: stealc,lumma
exclude=
# Community
[reversinglabs]
enabled = no
url =
key =
# Community
[script_log_processing]
enabled = yes
[html_scraper]
enabled = no
# Community
[polarproxy]
# Enable when using the PolarProxy option during analysis. This will merge the tls.pcap containing
# plain-text TLS streams into the task PCAP.
enabled = no
# Code-similarity engine(s). See conf/integrations.conf [similarity].
[similarity]
enabled = no
# Threat-intelligence enrichment. Engine and API settings live in
# conf/threat_intel.conf.
[threatintelligence]
enabled = no