Replies: 5 comments
-
sorry Not a team (unfortunately). I'm just on my own.
Application is released as an open source therefore any one can recompile and sign the application.
I have not been able to look through all elements but at least I can say:
The detection looks like a false positive : you should be able to report it for deeper analysis.
Hoping this will help you and feel free to star the project. |
Beta Was this translation helpful? Give feedback.
-
@pubpub-zz Thank you for taking out time in reviewing few of the detections., Much appreciated ! Would you be kind enough in reviewing the attached document ( 23 Detections) and provide your inputs, detection by detection. This will help us to whitelist the application and this tool will be deployed and used by our company globally. doable? ppInk.exe _ Sandbox _ Counter Adversary Operations _ Dynamic Analysis.pdf |
Beta Was this translation helpful? Give feedback.
-
I've added my comments. If you finally deploy ppInk in your company, :
|
Beta Was this translation helpful? Give feedback.
-
Certainly, Please guide me how to go about starring the project? |
Beta Was this translation helpful? Give feedback.
-
|
Beta Was this translation helpful? Give feedback.
-
Hello Team, we are trying to whitelist this app but we have encountered these issues by our Infosec team.
Why this app is not digitally signed by a trusted CA?
This app is flagged as Suspicious during sandbox analysis. Attached report for reference from Falcon CrowdStrike
ppInk.exe _ Sandbox _ Counter Adversary Operations _ Dynamic Analysis.pdf
ppInk.exe _ Sandbox _ Counter Adversary Operations _ Intelligence.pdf
ppInk.exe _ Sandbox _ Counter Adversary Operations _ Mitre Attack.pdf
ppInk.exe _ Sandbox _ Counter Adversary Operations _Static Analysis.pdf
Virus total >> https://www.virustotal.com/gui/file/73fe4fef701bf731274e6e7efd97a1a91566e842ba44f70230fb81e433240736/details
Are these detections false positive? if yes, can they be safely ignored?
Request your Kind confirmation.
Beta Was this translation helpful? Give feedback.
All reactions