So you're saying it's not good practice to use VirusTotal?thevampire said:There is a possibilty that the tools you downloaded are just RATs. Always open these tools in RDP or VPS.
Create your own sandbox with Oracle VirtualBox here : https://www.virtualbox.org/
Run your tools there and disable Windows Defender. Always download tools from trusted sources.
However, it's not good practice to test your tools with Antivirus(es), you can analyze the tools on VirusTotal(or other) by uploading it on their website or by checking the hash of the tool.
Nope 'cause they send every tool to analyze by their experts. So if there is a private RAT tool which is not yet flagged by the AVs and you test it on a bunch of sites, it will get flagged eventually. That's why it's recommended to run the tools on sandbox or RDP/VPS.RobtheGold said:So you're saying it's not good practice to use VirusTotal?
It's like we're uploading private/paid tools on a random site, and they can do whatever they want with it.
Got it, thank you!thevampire said:Nope 'cause they send every tool to analyze by their experts. So if there is a private RAT tool which is not yet flagged by the AVs and you test it on a bunch of sites, it will get flagged eventually. That's why it's recommended to run the tools on sandbox or RDP/VPS.
So do you download them in sandbox?thevampire said:Nope 'cause they send every tool to analyze by their experts. So if there is a private RAT tool which is not yet flagged by the AVs and you test it on a bunch of sites, it will get flagged eventually. That's why it's recommended to run the tools on sandbox or RDP/VPS.
Thanks so much for the info - one last question... How do you disable he windows defender in a sandbox?thevampire said:Yes download tools that you don't trust in Sandbox. In fact, even PDFs or image files downloaded from unknown sources should be opened in Sandbox. There can be a backdoor even in image files. That's why for precaution, these things should be run in SandBOX.
Should i be downloading stuff directly into the virtual box or can i drag and drop from host pc to VM?thevampire said:Do this. Download VirtualBox from Oracle and install any Windows there and test the tools inside the V-BOX or open any files in there. I use Virtual box or RDP for these types of things. There you can disable Windows Defender.
Check how to disable Defender here :
https://support.microsoft.com/en-us...security-99e6004f-c54c-8509-773c-a4d776b77960