Installing and using Cuckoo Sandbox
As we have seen, public analysis tools are incredibly useful, and provide a wealth of information, though not every tool provides the same information. One weakness of public sandboxing utilities and public analysis tooling in general lies within the classification: they are public.
Because these tools are public, it is possible for either the owner of the sandbox or the community at large to access samples that may contain valuable internal information related to your employer's environment.
As a result of this, many companies prefer to not submit malware samples to public sandboxes and have instead elected to build their own sandboxing platform with the open source software Cuckoo, which is available for macOS, Linux, and Android. The Cuckoo platform consists of a *nix
server, and a customized, vulnerable Windows 7 VM that will be spun up on demand in order to detonate malware.
In the next few sections, we'll examine what the...