Upload a executable file to be analyzed under EDR.
Your executable file to be analyzed under EDR.
The VM / EDR you want to test against.
AutoIt most realistic. Will "click" the file. Maybe unreliable. Also supports .zip, .iso. Direct child execution. Will "CreateProcess()" it. Reliable. Supports .exe with arguments. And .dll. Clickfix will interpret the content of the file as single line string to be inserted into the Windows run dialog.
[Optional] .EXE: Command line parameters [Mandatory] .DLL: Exported function name to invoke
How long the payload and VM is allowed to run.
Accepted range: 3 - 7200 seconds. Default 10 seconds.
This analysis profile requires password authentication. Enter the password to proceed with the analysis.
The target directory path where the malware should be initially placed on the virtual machine
Default: C:\Users\Public\Downloads\ Whitelisted execution: C:\RedEdr\data\
C:\Users\Public\Downloads\
C:\RedEdr\data\
[Optional] URL pointing to more information about the payload
[Optional] Description of the payload. What loader, C2 payload etc.
[Optional] Description of what you're testing or trying to achieve with this analysis. Include your hypothesis, what detection capabilities you're evaluating, or research objectives
[Optional] project name to group related submissions together