Feb 15,2010

New ISC Tool: Whitelist Hash Database, (Mon, Feb 15th)

NIST is publishing a regularly updated set of CDs with hashes for a number of software packages. The National Software Reference Library (NSRL) is frequently used for forensics to eliminate unaltered standard files from an investigation. However, I feel that this database also has a lot of use for malware analysis. Anti-malware software usually takes an enumerate badnessapproach in attempting to come up with signatures for all known malware. With the current flood of new malware variants, this approach does not work well anymore. One problem with the NIST NSRL was that there was no easy way to look up ...

Filed Under: SANS Internet Storm Center, Tags: ,

Leave a Reply