CloneRanger wrote:@ ssj100The problem with the line of argument you're using is that how does one actually define a realistic real world environment? If you think about it, scientifically, using a fresh install is the best method of testing whether something works. Then, if you confirm that it works, you could go on and test it with Shadow Defender installed. Then, if that still worked, you could go on and test it with services disabled etc etc. Do you see the point I'm making? I'm essentially talking about the principle of a "fair test" methodology.
why did you disable your other security software?If i hadn't they wouldn't have even been able to run, due to either .EXE blocking and/or AV etc detection. Not to eliminate third party variations.
Sure i ran then with SD enabled, but that wouldn't interfere with the POC's.
If every piece of malware had to ask people to do a fresh install first and/or run in a VM etc, where would that get them. I run tests in a realistic real world enviroment. First with all my security in place to see if they block/interject etc, then one by one i disable them and see what happens, or not. The main purpose of most tests etc i do, is to see how my security shapes up, or not. It it does great, if not i improve it.
If EP_X0FF used Shadow Defender (as well as disabled services etc) to test his POC, then sure, the principle of a "fair test" would require we use Shadow Defender and disable services etc, at least when initially attempting to reproduce the POC.
You missed the point I was making about ProcessGuard - by disabling it, you have by definition eliminated one more aspect of third party variation. The POC simply failed to run with ProcessGuard enabled - therefore you disabled it. But then the POC still fails for your setup right? Therefore, you can now take further steps to reduce third party variations in order to reproduce the POC. And as I said, the best way to reduce third party variations is to implement testing fairly - a fresh install of Windows followed by a Prevx installation would be ideal. With VirtualBox (or any VM software), this is very easily achieved.
EDIT: by the way, latest POC (not released to public) still works and is not detected by Prevx. Shame.
Sandboxie + LUA + SRP + DEP + SuRun
Windows Firewall + NAT Router + IPSec (on-demand)
VirtualBox (on-demand)
Drive SnapShot (on-demand)
Windows Firewall + NAT Router + IPSec (on-demand)
VirtualBox (on-demand)
Drive SnapShot (on-demand)