Loading...

New Submission

Upload a executable file to be analyzed under EDR.

File *

Your executable file to be analyzed under EDR.

Submission Profile *

The VM / EDR you want to test against.

Submission Execution Mode *

AutoIt most realistic. Will "click" the file. Maybe unreliable. Also supports .zip, .iso.
Direct child execution. Will "CreateProcess()" it. Reliable. Supports .exe with arguments. And .dll.
Clickfix will interpret the content of the file as single line string to be inserted into the Windows run dialog.

Runtime (seconds)*

How long the payload and VM is allowed to run.

Accepted range: 3 - 7200 seconds. Default 10 seconds.

Submission Malware Execution Path

The target directory path where the malware should be initially placed on the virtual machine

Default: C:\Users\Public\Downloads\
Whitelisted execution: C:\RedEdr\data\

File Source URL

[Optional] URL pointing to more information about the payload

File Comment

[Optional] Description of the payload. What loader, C2 payload etc.

Submission Comment

[Optional] Description of what you're testing or trying to achieve with this analysis. Include your hypothesis, what detection capabilities you're evaluating, or research objectives

Submission Project

[Optional] project name to group related submissions together