Commit Graph

153 Commits

Author SHA1 Message Date
Alberto Ortega
6264d96ca2 Function to read HV vendor information, added to logging 2016-03-02 20:27:03 +01:00
Alberto Ortega
a6a0478915 Bump v056 2015-12-28 16:26:18 +01:00
Alberto Ortega
21efd60b45 Disabled check_hook_DeleteFileW_m1 because it causes FP in Win 8 2015-12-28 16:21:38 +01:00
Alberto Ortega
1c7d5c3f2b Update README 2015-12-28 13:58:46 +01:00
Alberto Ortega
9ab9e0fb3b re #46 add IsNativeVhdBoot detection 2015-12-27 12:25:53 +01:00
Alberto Ortega
896f26f3be Fixes warning in latest mingw 2015-12-27 12:17:18 +01:00
Alberto Ortega
7420c27542 re #43 Include a DNS request for each detection, useful in restrictive sandboxes 2015-12-23 19:42:13 +01:00
Alberto Ortega
eac42caae3 re #45 Add uptime test 2015-12-22 21:12:54 +01:00
Alberto Ortega
6b27791837 Bump v055 2015-10-08 19:32:01 +02:00
Alberto Ortega
feeba7ba8e Minor includes changes 2015-10-08 19:22:39 +02:00
Alberto Ortega
72296dacd6 Disable a not so reliable bochs check 2015-10-08 19:14:27 +02:00
Alberto Ortega
044760116a Refactor of hooks detection function, add 2 more functions to check 2015-09-04 18:24:53 +02:00
Alberto Ortega
54f33a2929 Minor refactor in GetAdaptersAddresses functions 2015-08-30 18:44:49 +02:00
Alberto Ortega
017d5dfbbd Add VMware detection based on network adapter name 2015-08-30 18:35:22 +02:00
Alberto Ortega
618037ba25 indent -linux main.c 2015-08-30 01:34:07 +02:00
Alberto Ortega
cc31829b45 Minor includes change 2015-08-29 14:06:17 +02:00
Alberto Ortega
b0b72c4e5e Refactor main.c, link new Qemu and Bochs detections in main 2015-08-29 13:55:42 +02:00
Alberto Ortega
ea6617f45b Add Bochs detections based on CPU information 2015-08-29 00:49:41 +02:00
Alberto Ortega
c65cfb5adc Add new qemu detection based on CPU brand string 2015-08-29 00:29:41 +02:00
Alberto Ortega
94dca540db Add cpu functions to query Processor Brand String 2015-08-28 23:12:07 +02:00
Alberto Ortega
89cf87ead9 re #40 add neutrino bochs detection via regkey 2015-08-26 19:09:52 +02:00
Alberto Ortega
49a6f3a447 Fix minor issue with wbemidl.h import 2015-08-26 19:07:25 +02:00
Alberto Ortega
4e434ba6f3 Bump v054 2015-07-12 17:26:26 +02:00
Alberto Ortega
3e322f2b97 Change hi_(vmware|virtualbox)_wmi for generic trace files 2015-07-12 17:15:13 +02:00
Alberto Ortega
4fe2cc3c91 5.4 candidate build 2015-07-11 12:54:08 +02:00
Alberto Ortega
3a564d60e7 Minor style change (cppcheck) 2015-07-11 12:51:29 +02:00
Alberto Ortega
bc9971f06e Merge branch 'serializingme-dev-hackingteam-v1' into dev-chaos 2015-07-11 11:50:17 +02:00
Duarte Silva
0d7d8fb43e Added HackingTeam anti-Cuckoo function as a check 2015-07-10 20:21:55 +01:00
Duarte Silva
229e1eb751 Added HackingTeam anti-VM WMI checks
- VirtualBox check of the device identifiers
- VMWare check of the serial number
2015-07-10 15:21:06 +01:00
Alberto Ortega
28d2889d0d Merge branch 'serializingme-dev-fixcompilewarn-v1' into dev-chaos 2015-07-08 12:37:09 +02:00
Duarte Silva
93f25aa6dc Fixed warning about redefined variables
- "KEY_WOW64_32KEY" redefined
- "KEY_WOW64_64KEY" redefined
2015-07-08 10:01:28 +01:00
Duarte Silva
1033f2818a Fixed warning "Please include winsock2.h before windows.h" 2015-07-08 09:59:00 +01:00
Alberto Ortega
887cdd4877 Bump v053 2015-06-02 19:42:31 +02:00
Alberto Ortega
6abe138edf Minor refactor in utils.c 2015-05-31 16:36:59 +02:00
Alberto Ortega
d957b6bcd1 Handle registry keys redirection in x86_64 2015-05-31 16:31:27 +02:00
Alberto Ortega
ea2888161b re #33 Add VMware MAC detection, minor refactor 2015-05-30 20:50:22 +02:00
Alberto Ortega
6cae2f7fa8 Merge branch 'serializingme-dev-memorycheck-v2' into dev-chaos 2015-05-30 20:09:36 +02:00
Alberto Ortega
9ae8cf6a81 Merge branch 'dev-memorycheck-v2' of https://github.com/serializingme/pafish into serializingme-dev-memorycheck-v2 2015-05-30 20:09:21 +02:00
Alberto Ortega
f46dcb8a57 Merge branch 'serializingme-dev-syswowfix-v2_1' into dev-chaos 2015-05-30 20:07:23 +02:00
Alberto Ortega
17108f3e55 Merge branch 'dev-syswowfix-v2' of https://github.com/serializingme/pafish into serializingme-dev-syswowfix-v2_1 2015-05-30 20:06:52 +02:00
Duarte Silva
7c591a0b2a Changed check from available to total physical memory. 2015-05-27 19:35:46 +01:00
Duarte Silva
20872a383f Typographical error correction. 2015-05-27 19:34:06 +01:00
Alberto Ortega
fd10ee553e Merge branch 'serializingme-dev-syswowfix-v1' into dev-chaos 2015-05-20 11:25:12 +02:00
Alberto Ortega
168f52cc58 Merge branch 'serializingme-dev-issue15-v1' into dev-chaos 2015-05-20 11:19:04 +02:00
Alberto Ortega
ea6e3cf704 Merge branch 'serializingme-dev-memorycheck-v1' into dev-chaos 2015-05-20 11:13:50 +02:00
Duarte Silva
2d2d410f31 Disabled Wow64 file system redirection:
- When running pafish in a 64 bits sandbox many file checks failed;
- This will allow for pafish to access the native system32 directory.
2015-05-18 16:12:54 +01:00
Duarte Silva
01ac4d2153 Added a check for less than one GiB of memory. 2015-05-18 15:22:49 +01:00
Duarte Silva
01879489d4 Added extra checks for VMWare and Wine. 2015-05-18 15:20:20 +01:00
Alberto Ortega
b0a2aeeda3 Merge branch 'serializingme-dev-fixlinuxcompile-v2' into dev-chaos 2015-05-16 13:30:55 +02:00
Duarte Silva
84060717c1 Removed unnecessary handling code. 2015-05-15 15:53:23 +01:00