Giter Club home page Giter Club logo

malice's Introduction

malice logo

NOTE: Malice's evolution continues here - https://github.com/maliceio/malice

malice (Deprecated)

Build Status Documentation Status Code Health Coverage Status License Support blacktop via Gittip Gitter Chat

VirusTotal Wanna Be

Malice's mission is to be a free open source version of VirusTotal that anyone can use at any scale from an independent researcher to a fortune 500 company.

It is a python Flask web app/api that can operate in standalone mode or as a distributed scalable web app.

I have been told that every serious information security team designs there own version of this tool. I want to build one so well designed and easy to use that everyone will stop recreating the wheel and instead use that time sharing intel and plugins with each other.

Requirements

  1. VirtualBox or VMWare
  2. Vagrant
Installing Requirements on OSX
$ brew install cask
$ brew cask install virtualbox
$ brew cask install vagrant

Installation

$ git clone https://github.com/blacktop/malice.git
$ cd malice
$ vagrant up

wait...

$ vagrant ssh
$ source ~/malice/venv/bin/activate
(venv)$ python /vagrant/manage.py createdb

Note: for additional notes please see the Malice wiki

Usage

(While ssh'd into the VM via vagrant ssh)

$ source ~/malice/venv/bin/activate
(venv)$ python /vagrant/manage.py runserver

Then browse to http://127.0.0.1:5000

Home

malice logo

Samples

malice logo

Analysis

malice logo

Documentation

Documentation is comming soon.

Testing

To run the tests (in the project directory):

$ pip install nose coverage
$ nosetests --with-coverage --cover-html -s

Road Map

  1. Get Malice to a stable 1.0 release
  • Finalize plugin arch
  • Finish default db arch (MongoDB)
  • Finalize python-rq distributed tasking
  • Finish documentation
  • Finish test suite
  • Integrate in to CI framework
  • Docker-ize Malice
  1. Windows based AV scanners

  2. Auto deployable Cuckoo Sandbox cluster that integrates into Malice

  • Create Salt or Ansible provisioners to auto spin up hardened Cuckoo VMs.
  1. Design a cluster dashboard and admin interface so sys admins can monitor Malice’s health and be alerted to issues.

  2. Malice will be designed in a way to auto scale under load (similar to the way that AWS does with Lambda etc)

  3. Possible make Malice’s default OS be CoreOS so that I can update the OS and all it’s plugins at the same time without interrupting processing allowing for zero downtime updates.

  4. Redesign Salt provisioners (maybe switch to Ansible?)

  • Make them work on any environment and use the templates to make it easy for users to enter their subscriptions API keys and AV licenses etc at installation.
  1. Redesign Web UI (maybe with ReactJS + Flex?)
  • I want to REALLY hipster it up and make it as performant as possible to MANY people can be using it at the same time without noticeable performance degradation (I will also be using load balancing and cacheing to achieve this)
  • As well as a full UI/UX revamp.
  1. Redesign Distributed Task Engine using Docker and Orchestration framework (Mesos, Kubernetes or Swarm)
  • I want to use these new emerging technologies to make the whole internet seem as one computer to Malice.
  1. Design a sharable IOC framework that works with Malice so that all Intel gained with Malice can easily be shared amongst users.
  • People hate sharing so I want to make it so easy to it will succeed.
  1. Redesign plugin framework to user docker containers that have their own Github accounts to take advantage of their star system (similar to the way atom.io uses it)
  • I have always wanted the plugins to be containerized. This will allow them to be easily integrated into Malice and allows for the idea of a Malice plugin market place where people could sell commercial plugins for Malice.
  • The plugins will also have built in test suites so that a non-functional or buggy plugin will never be mistakenly installed into Malice.
  1. I have another repo 'parking space' for Notorious with is going to be the Intel Framework designed t be tightly integrated into Malice and will most likely be an ELK stake with some customized searching/hunting capabilities as well as alerting. Essentially it will be VirusTotal Splunk.

  2. Design a crowd sourced way to have a hosted server that community can use and have free access to all the data.

  • Design the framework in a way so that anybody can host docker workers on their cloud or local machine to lend processing cycles to the Malice cluster. This is like the bitcoin concept except for a web app, much care must be taken when having untrusted samples be analyzed on people’s machines (which might limited it to just sandboxed static analysis) So instead of having to charge people for access to the data like how VirusTotal does, anyone that donate processing power to Malice get's full access to the private API.
  1. Add volatile analysis by integrating into Volatility or Rekall to analyze memory dumps extracted from Cuckoo Sandboxes.

  2. Add support for OSX analysis. Static, Dynamic and Volatile.

  3. Add support for mobile (iOS, Android, Windows) analysis. Static, Dynamic and Volatile (if possible)

  4. Add commenting and voting similar to the way that VirusTotal does it.

Contributing

  1. Fork it.
  2. Create a branch (git checkout -b my_malice)
  3. Commit your changes (git commit -am "Added Something Cool")
  4. Push to the branch (git push origin my_malice)
  5. Open a Pull Request
  6. Wait for me to figure out what the heck a pull request is...

Analytics

malice's People

Contributors

black-top avatar blacktop avatar

Watchers

 avatar  avatar

Recommend Projects

  • React photo React

    A declarative, efficient, and flexible JavaScript library for building user interfaces.

  • Vue.js photo Vue.js

    🖖 Vue.js is a progressive, incrementally-adoptable JavaScript framework for building UI on the web.

  • Typescript photo Typescript

    TypeScript is a superset of JavaScript that compiles to clean JavaScript output.

  • TensorFlow photo TensorFlow

    An Open Source Machine Learning Framework for Everyone

  • Django photo Django

    The Web framework for perfectionists with deadlines.

  • D3 photo D3

    Bring data to life with SVG, Canvas and HTML. 📊📈🎉

Recommend Topics

  • javascript

    JavaScript (JS) is a lightweight interpreted programming language with first-class functions.

  • web

    Some thing interesting about web. New door for the world.

  • server

    A server is a program made to process requests and deliver data to clients.

  • Machine learning

    Machine learning is a way of modeling and interpreting data that allows a piece of software to respond intelligently.

  • Game

    Some thing interesting about game, make everyone happy.

Recommend Org

  • Facebook photo Facebook

    We are working to build community through open source technology. NB: members must have two-factor auth.

  • Microsoft photo Microsoft

    Open source projects and samples from Microsoft.

  • Google photo Google

    Google ❤️ Open Source for everyone.

  • D3 photo D3

    Data-Driven Documents codes.