Using Hyper-V Sockets for Real-time Data Extraction from a Malware Analysis Sandbox
István-Attila Császár, Radu-Marian Portase, Adrian Coleşa, Adrian Groza
Abstract
We present how Hyper-V sockets can be used as a real-time communication channel for a malware analysis sandbox. We show that, compared to WinSock TCP sockets, Hyper-V sockets are not subject to TCP/IP-layer blocking and are not enumerated by common TCP connection listing tools. We compare the throughput of the two communication channels as a function of buffer size.
Create a lesson
Related papers
Attesting Outputs and Delegation Ancestry in Multi-Agent AI Systems
Lifei Liu, Haoran Yu
KORD: Breaking the Key-Generation Bottleneck in Dealerless FSS via Protocol--Hardware Co-Design
Yijing Peng, Lin Liu, Yujie Xue et al.
A Roadmap to Available ICS Datasets and Testbeds for Cybersecurity Research
Ebtesam J. Alqahtani, Mohammad Hammoudeh
Extracting Knowledge from Tools in LLM Agents
Chuanchao Zang, Jianing Wang, Wenyu Chen et al.
SIR: Self-improving Red-teaming for Compute Use Agents
Chen Xiong, Zhiyuan He, Pin-Yu Chen et al.
Understanding Stage-Wise Utility-Risk Trade-offs in LLM Agent Memory
Chuanchao Zang, Zijian Cao, Xiangtao Meng et al.