You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Hi,
I’m currently running malware samples in an isolated VM and using Tracee to capture events. However, I’ve encountered an issue where I’m not able to capture certain IOCs, such as file drops, network connections, and process-related events, in the Tracee logs.
The IOCs are detected when I analyze the samples using Joe Sandbox, but I cannot see them in the Tracee logs.
Here are the filters I’m using for Tracee:
Despite using these filters, I’m not getting the expected events. I’m not sure what I might be doing wrong or if I need to adjust the filters in some way.
Would anyone have suggestions or advice on how to ensure I capture all possible IOCs, specifically those related to file drops, network connections, and processes? For now, I’d like to start with a comprehensive set of filters, and once I have more data, I can optimize further.
I’d appreciate any help or guidance.
Thank you!
The text was updated successfully, but these errors were encountered:
Hi,
I’m currently running malware samples in an isolated VM and using Tracee to capture events. However, I’ve encountered an issue where I’m not able to capture certain IOCs, such as file drops, network connections, and process-related events, in the Tracee logs.
The IOCs are detected when I analyze the samples using Joe Sandbox, but I cannot see them in the Tracee logs.
Here are the filters I’m using for Tracee:
Despite using these filters, I’m not getting the expected events. I’m not sure what I might be doing wrong or if I need to adjust the filters in some way.
Would anyone have suggestions or advice on how to ensure I capture all possible IOCs, specifically those related to file drops, network connections, and processes? For now, I’d like to start with a comprehensive set of filters, and once I have more data, I can optimize further.
I’d appreciate any help or guidance.
Thank you!
The text was updated successfully, but these errors were encountered: