How do I test ransamware myself ?

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements
Please sign in to see details of an important advisory in our Customer Advisories area.

How do I test ransamware myself ?

L2 Linker
Hello, everyone of the specialist

I plan to settings for wannacry in the Pan-OS 8.1
I want to check in advance that the settings will work

But I can't have a real wannacry on my PC
So I'm worried about how to prepare a fake wannacry

Do you have a good idea

Thank you
 
~~~~japanese

こんにちは、スペシャリストの皆さん

私はPan-OS 8.1でwannacryに対する設定をする予定です

その設定が間違いなく動作するかを事前に確認したいです

ですが、私が本物のwannacryをPCに用意するわけにはいかないです

そこで、偽のwannacryをどうやって用意するかを悩んでいます

良いアイデアはありますか

ありがとう

 

 

3 REPLIES 3

Cyber Elite
Cyber Elite

@awawa100,

The firewall itself can only prevent you from downloading the file in the first place, so testing this won't actually require you to run anything. Ransomware samples are prevelant; try to download some and if it actually downloads successfully.

The firewall should really only be one of the layers involved in your defence, and I wouldn't rely on it actually stopping users from downloading ransomware. If you are fully decrypting the traffic it should be able to catch files already identified by WildFire, but that only goes so far. I would recommend that you ensure you have something like Traps or CrowdStrike installed on your endpoints, as they both actually serve to stop the ransomware from actually locking down the system or spreading within your network. 

 

When it comes to actual testing you don't do malware testing on just any machine. You want to make it so that the machine you are using for testing is actually isolated from anything else on your network if it needs any network connectivity at all; and I would generally recommend utilizing a sandboxed VM on an isolated host.

Hello,

Please listen to what BPry is saying. Always use a test machine and make sure its segregated from the rest of the network. If you subscribe to wildfire, you can test it as they have a test file to use.

 

https://wildfire.paloaltonetworks.com/wildfire/account

 

Regards,

L2 Linker
Experts
Thanks for some advice

We chose metasploit as a penetration tool

I was able to see the threat alert

Thank you everyone
 
日本語~~~~~

エキスパートの皆さん
いくつかのアドバイスをありがとう

ぺネストレーションのツールとして、metasploitを選びました

脅威のアラートを確認することができました

みなさん、ありがとうございました

 

 

  • 2567 Views
  • 3 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!