Jump to content
Usr6

Capture BAT

Recommended Posts

Posted

2011-11-05_011328.png

Capture BAT is a behavioral analysis tool of applications for the Win32 operating system family. Capture BAT is able to monitor the state of a system during the execution of applications and processing of documents, which provides an analyst with insights on how the software operates even if no source code is available. Capture BAT monitors state changes on a low kernel level and can easily be used across various Win32 operating system versions and configurations.

Capture BAT provides a powerful mechanism to exclude event noise that naturally occurs on an idle system or when using a specific application. This mechanism is fine-grained and allows an analyst to take into account the process that cause the various state changes. As a result, this mechanism even allows Capture to analyze the behavior of documents that execute within the context of an application, for example the behavior of a malicious Microsoft Word document

The program has a console interface and a small set of parameters:

-L output.txt output to a file.

-C Copy all the deleted or modified files folder logs

-N Save all incoming and outgoing traffic to a file. Pcap in logs

-H Displays help

Prerequisites:

  • Microsoft Windows 2000 sp 4; Microsoft Windows XP sp 2; for Microsoft Vista no service pack is needed.
  • Microsoft Visual C++ 2005 Redistributable Package
  • f the network dump functionality is used, Capture BAT requires the WinPcap 4.0.1 libraries.

The application will be installed into C:\program files\capture. Note that a reboot will be forced by the setup program.

CaptureBAT.exe -cn-l report.txt

report.txt

Download:

http://www.mcs.vuw.ac.nz/~cseifert/Capture-BAT/CaptureBAT-Setup-2.0.0-5574.exe MD5: c1894e46ffe89be6ca35729d9dab6145

http://www.mcs.vuw.ac.nz/~cseifert/Capture-BAT/CaptureBAT-Setup-2.0.0-5574-src.zip MD5: 0086e7c01e481992284092ea0f9de20f

surse:1,2

  • Upvote 1

Join the conversation

You can post now and register later. If you have an account, sign in now to post with your account.

Guest
Reply to this topic...

×   Pasted as rich text.   Paste as plain text instead

  Only 75 emoji are allowed.

×   Your link has been automatically embedded.   Display as a link instead

×   Your previous content has been restored.   Clear editor

×   You cannot paste images directly. Upload or insert images from URL.



×
×
  • Create New...