CBLK Carbon Black

Carbon Black Threat Analysis Unit (TAU) Launches “Binee,” an Open-Source Binary Emulator for Malware Researchers at DEF CON 27

Carbon Black Threat Analysis Unit (TAU) Launches “Binee,” an Open-Source Binary Emulator for Malware Researchers at DEF CON 27

LAS VEGAS, Aug. 10, 2019 (GLOBE NEWSWIRE) -- DEF CON 27 --  (NASDAQ: CBLK), a leader in cloud-native endpoint protection, today announced the launch of “Binee,” an open-source binary emulator that bridges the gap between static and dynamic analysis of real-world malware. Binee empowers researchers to extract run-time data from binaries at a cost, speed and scale previously only possible with static analysis tools, opening up a wealth of run-time malware data for behavioral analysis and machine learning applications.

Carbon Black’s Threat Analysis Unit (TAU) researchers Kyle Gwinnup () and John Holowczak () revealed the tool, whose name is short for “Binary Emulation Environment,” during their presentation, “” at in Las Vegas on Saturday, August 10.

_________________

Click here to access “Binee” via .

_________________

Malware detection through standard static analysis has become increasingly difficult and researchers are becoming more reliant on dynamic analysis techniques to understand the behavior of the malware they are studying. Unfortunately, dynamic analysis is costly and time-consuming, meaning only a very small portion of it can be assessed in this way. Binee addresses this gap – delivering run-time analysis of malware at the speed and cost of static analysis through mock process emulation.

The ability to emulate x86 and other architectures has been around for some time – malware analysts have several tools readily available in the public domain. However, most of the tools stop short of full emulation, either halting or doing strange things when emulating library functions or system calls not implemented in the emulator.

Binee creates a nearly identical Windows process memory model inside the emulator, including dynamically loaded libraries and other Windows process structures. Binee mimics much of the OS kernel and outputs a detailed description of all function calls with human readable parameters throughout the duration of the process, providing greater insight into a malware’s API calls and other IOCs than static analysis. Binee offers the ability to extract features of a binary that were only visible to dynamic binary analysis, with a cost closer to that of static analysis.

The team has designed the tool with two primary use cases in mind. First, for data extraction at scale with a cost and speed similar to common static analysis tools and, second, for malware analysts that need a custom operating system and framework without the overhead of spinning up various configurations of virtual machines.

“Binee can be used as a critical part of a malware analysis funnel – allowing security professionals to identify and analyze behavioral attributes of malware,” the researchers said. “This, in turn, opens up a huge new data set for behavioral analysis and machine learning that improves detection capabilities. We’ve decided to open source this tool because building a Windows emulator is hard and, due to the immense value it provides malware researchers, we want more people working on it, accelerating development and driving a more complete emulator, faster.”

Currently, Binee can run on Windows, OS X, and Linux.

_________________

Click here to access “Binee” via .

_________________

About Carbon Black

Carbon Black (NASDAQ: CBLK) is a leader in cloud-native endpoint protection dedicated to keeping the world safe from cyberattacks. The CB Predictive Security Cloud® (PSC) consolidates endpoint protection and IT operations into an endpoint protection platform (EPP) that prevents advanced threats, provides actionable insight and enables businesses of all sizes to simplify operations. By analyzing billions of security events per day across the globe, Carbon Black has key insights into attackers’ behaviors, enabling customers to detect, respond to and stop emerging attacks.

More than 5,600 global customers, including approximately one third of the Fortune 100, trust Carbon Black to protect their organizations from cyberattacks. The company’s partner ecosystem features more than 500 MSSPs, VARs, distributors and technology integrations, as well as many of the world’s leading IR firms, who use Carbon Black’s technology in more than 500 breach investigations per year.

Carbon Black and CB Predictive Security Cloud are registered trademarks or trademarks of Carbon Black, Inc. in the United States and/or other jurisdictions.

Contact

Ryan Murphy, Carbon Black

Director of Global Communications

917-693-2788

EN
10/08/2019

Underlying

To request access to management, click here to engage with our
partner Phoenix-IR's CorporateAccessNetwork.com

Reports on Carbon Black

 PRESS RELEASE

Carbon Black’s Second Canada Threat Report Reveals Growing Defender ...

Carbon Black’s Second Canada Threat Report Reveals Growing Defender Confidence Despite Sustained Threat Levels 88% of surveyed Canadian businesses report breaches, primarily caused by phishing attacks WALTHAM, Mass., Oct. 01, 2019 (GLOBE NEWSWIRE) -- Carbon Black, (NASDAQ: CBLK), a leader in cloud-native endpoint protection, today released the results of its second , based on a survey of 250 CIOs, CTOs and CISOs across Canada. The results show that the threat environment is sustained and sophisticated with phishing attacks serving as the primary cause of data breaches. Key research fin...

 PRESS RELEASE

Carbon Black Named a Visionary in Gartner Magic Quadrant for Endpoint ...

Carbon Black Named a Visionary in Gartner Magic Quadrant for Endpoint Protection Platforms for Third Consecutive Year As a Visionary in Gartner’s latest Magic Quadrant for Endpoint Protection Platforms, Carbon Black was recognized for its ability to execute and completeness of vision WALTHAM, Mass., Aug. 27, 2019 (GLOBE NEWSWIRE) -- , a leader in cloud-native endpoint protection, today announced it was named a Visionary in the Gartner Magic Quadrant for Endpoint Protection Platforms (EPP) for the third consecutive year. Carbon Black believes placement in the Visionaries quadrant validat...

 PRESS RELEASE

Carbon Black to Keynote Federal Financial Institutions Examination Cou...

Carbon Black to Keynote Federal Financial Institutions Examination Council’s 2019 Information Technology Conference WALTHAM, Mass., Aug. 27, 2019 (GLOBE NEWSWIRE) -- (), a leader in cloud-native endpoint protection, today announced that its Chief Cybersecurity Officer, Tom Kellermann, will keynote the Information Technology Conference, hosted by the Federal Financial Institutions Examination Council (FFIEC) in Arlington, VA. Carbon Black’s keynote presentation is scheduled for Tuesday, August 27, 2019 from 8:45 a.m. to 9:45 a.m. Eastern time. The Information Technology Conference is di...

 PRESS RELEASE

Carbon Black Threat Analysis Unit (TAU) Launches “Binee,” an Open-...

Carbon Black Threat Analysis Unit (TAU) Launches “Binee,” an Open-Source Binary Emulator for Malware Researchers at DEF CON 27 LAS VEGAS, Aug. 10, 2019 (GLOBE NEWSWIRE) -- DEF CON 27 --  (NASDAQ: CBLK), a leader in cloud-native endpoint protection, today announced the launch of “Binee,” an open-source binary emulator that bridges the gap between static and dynamic analysis of real-world malware. Binee empowers researchers to extract run-time data from binaries at a cost, speed and scale previously only possible with static analysis tools, opening up a wealth of run-time malware data for b...

 PRESS RELEASE

Carbon Black Delivers New API Capabilities and Access Control on Its C...

Carbon Black Delivers New API Capabilities and Access Control on Its Cloud-Native Endpoint Protection Platform (EPP) New API Access Control offers critical flexibility in data management, enabling better, more secure integrations CB LiveOps API extends the benefits of real-time endpoint query and remediation across the security stack LAS VEGAS and WALTHAM, Mass., Aug. 08, 2019 (GLOBE NEWSWIRE) -- BLACK HAT USA 2019 — (CBLK), a leader in cloud-native endpoint protection, today announced customizable API Access Control across the company’s cloud-native endpoint protection platform (EPP). ...

ResearchPool Subscriptions

Get the most out of your insights

Get in touch