CybercentreCanada / assemblyline-service-avclass

Assemblyline 4 service that extracts malware family and details from AV labels

Home Page:https://cybercentrecanada.github.io/assemblyline4_docs/

Geek Repo:Geek Repo

Github PK Tool:Github PK Tool

AVClass Service

Consumes Anti-Virus tags (av.virus_name) and extracts family, behavior, and platform information based on AVClass2.

Configuration

The service has no parameters, but relies on the following files, as described in the AVClass2 documentation.

These configurations differ from defaults provided by AVClass2 in that they were generated using a large quantity of VirusTotal submissions. Configuration should be periodically updated to ensure that new malware families and behaviors are correctly extracted.

About

Assemblyline 4 service that extracts malware family and details from AV labels

https://cybercentrecanada.github.io/assemblyline4_docs/

License:MIT License


Languages

Language:Python 98.8%Language:Dockerfile 1.2%