Cyber forensic tools play a crucial role in cyber investigations by helping investigators collect, analyze, and preserve digital evidence.
These tools can extract data from various sources, such as:-
They also allow for identifying malware, tracking online activities, and decrypting encrypted data.
Recently, Any Run launched its new “Script Tracer,” a tool primarily made for threat researchers to trace and deobfuscate malware execution.
ANY.RUN is an interactive malware sandbox that allows users to analyze unlimited malicious files and links for free. It also has a dedicated team of analysts who continuously expand the service’s detection and analysis capabilities.
Analyzing any suspicious attachment or URL in a free interactive malware sandbox like ANY.RUN can instantly provide you with a conclusive verdict.
Script Tracer in ANY.RUN’s cloud sandbox simplifies script deobfuscation and works seamlessly across all the major Windows versions, like Windows 7-11, enhancing users’ experiences.
Scripting languages empower Windows tasks but also fuel rising malware in such code. There are various types of scripting code in Windows, and here they are mentioned below:-
All the above-mentioned scripts can be analyzed seamlessly with the help of Script Tracer. Before this update, ANY.RUN users saw execution outcomes but not attackers’ script actions like:
Script Tracer provides detailed insights into deobfuscated script activities, similar to code debugging. Besides this, access the Script Tracer reports from a tracer icon in the process tree or the Advanced Process Details report.
Here below, we have mentioned the two new additions:
Apart from this, this tracer also enables users to view compiled VBE scripts like:-
Script Tracer reveals hidden insights, like request results. Scripts run via executables, as with WMIC loading and executing vbscript for malware data collection.
Encountering VBS-based malware? Examine WSHRat as an example. Easily investigate Office macros and scripts. You can also delve into the visible Windows API in a sneaky document using “alloc” and “request.”
Implementing ANY.RUN’s Threat Intelligence products are simple. Contact the Any Run team to learn more.
Patch Manager Plus: Automatically Patch over 850 third-party applications quickly – Try Free Trial.
Cybersecurity Risk Management – 6 Best Practices
GitLab 12.6 Released With Tools to Track Project Security Status and Release Evidence
Google has released an important Chrome 153 security update that fixes 42 vulnerabilities across the…
The Cybersecurity and Infrastructure Security Agency (CISA) and the National Institute of Standards and Technology…
CISA and five international cybersecurity agencies have released detailed guidance describing 17 common techniques hackers…
Apple has released one of its largest coordinated security rollouts, addressing 273 distinct critical vulnerabilities…
You can’t detect today's attacks with yesterday’s threat intelligence; that’s how you could briefly formulate…
Microsoft has published a draft Humanist AI Code of Conduct that would prohibit its in-house…