log2timeline
Looks pretty neat… for free…
…a tool that could take timeline analysis to a new level. That is to create a single tool that could parse various artifacts found on a suspect drive and include them in the timeline, a some sort of super timelining…
via log2timeline.
The Irrelevancy of Industry Accepted Malware Testing Standards
I have to say that DannyQuist has it right. The AV industry is not real world and not effective. The fact remains that the AV industry is about selling signatures, not about preventing malware from infesting your PC. The fact that they can take a finger print of what they’ve found “in the wild” is NOT proof that they are effective. It only proves that they are blinded by the model of selling signatures to customers. If they could detect bad behaviors or do more intelligent signature matches, they might actually pass the types of tests that DannyQuist is proposing. But the AV industry is happy to only protect you against yesterday’s threat, and keep playing casualty vampire to feed their need for more things to take signatures of.
The primary reason that the AV industry is so sensitive about their software is because it is not as effective as they would like you to believe. Case in point is the recent Anti-Malware Testing Standards Organization’s document titled Issues involved in the ‘creation’ of samples for testing. If you want to find a document listing all the hot-button issues that particularly perturb the AV community, here it is.
via The Irrelevancy of Industry Accepted Malware Testing Standards | Offensive Computing.











