Skip to content
Felix Bauer edited this page Nov 30, 2022 · 34 revisions

Welcome to the PeekabooAV wiki!

Peekaboo Extended Email Attachment Behavior Observation Owl

The administration and development documentation is contained in the code repository:

Here we host the more abstract view on the concept:

  • PeekabooAV is an Anti Virus software. For a server setup see Server Concept
  • It gets email attachments from AMaViSd, checks them, uses Cuckoo for behavioral checks, and evaluates and rates fully automatic, see Sample Lifecycle
  • PeekabooAV is written in Python, multi-threaded, scalable, has a very powerful ruleset, and is easy to extend and personalize
  • It is able to detect: malware by its behavior, exploitation of zero days, and targeted attacks
  • Tidbits when running Peekaboo atop Proxmox
  • If you want to use the wonderful installer Felix wrote, check out PeekabooAV-Installer
  • Create your own rules with these steps to develop a new rule
  • We are looking for talented and passionate people - Want to work with us?

For news and announcements follow us on twitter @peekabooAV.

Developers

Felix Bauer, Sebastian Deiss, Christoph Herrmann

Awards

Dissertations / Academic work

  • Ader, Benjamin (2022) - Binary File Visualization für die Erkennung verschiedener Dateitypen durch maschinelle Bildklassifikation
  • Mähner, Yannick (2022) - Open Source Malware Sandboxes
  • Zichler, Daniel (2022) - Bestimmung der Indicators of Compromise für einen gezielten Angriff
  • Stanke, Daniel (2022) - Erkennung schädlicher Aktionen durch das Windows Eventlog mit Sysmon
  • Vömel, Niklar (2022) - Malware Hunting im Hauptspeicher von Windows Systemen
  • Marquard, Wüst (2021) - Fighting malspam with rspamd
  • Bühler, Widmayer (2021) - Security Scan verschlüsselter E-Mail-Anhänge anhand aus dem Mailtext generierter Wortlisten
  • Dettmann (2020) - Angriffe mit Windows Management Instrumentation
  • Faiß, Riethmüller (2020) - Living off the Land: Angriffe auf Microsoft Windows
  • Burkowitz (2020) - Signature Examination of Malware detection Sandboxes
  • Hegele (2020) - Härtung des Linux-Betriebssystems
  • Barkhüser, Höldin (2020) - Office Malware Triage
  • Geistler, Rauschke (2020) - Open-Source-Projekt PeekabooAV Regelwerkserstellung und Optimierung
  • Fischer (2019) - Erweiterung eines Open-Source-Projektes aus dem IT-Security- und Malware-Bereich
  • Schmid, Nonnenmann (2018) - Evaluierung und Erweiterung von PeekabooAV zur Detektierung von Malware in E-Mail
  • Stucki (2018) - IPA Proof of Concept (PoC) Mail-Security Gateway mit Verhaltensanalyse von Mailanhängen mittels Sandboxing

Conference Presentations