Hi,Everyone!
Capture-hpc is wonderful! I am a
newman who encountered a question about it recently.
My question is: "How to enable the
malwares to be downloaded from capture-client onto the capture-server?"
I had set the "collect-modified-files" item in the
"config.xml" to be "true",just as below:
<global collect-modified-files="true" client-default-visit-time="10"
capture-network-packets-malicious="false"
capture-network-packets-benign="false" send-exclusion-lists="false" p_m="0.019"
/>
<exclusion-list monitor="file" file="FileMonitor.exl" />
<exclusion-list monitor="process" file="ProcessMonitor.exl" />
<exclusion-list monitor="registry" file="RegistryMonitor.exl" />
But it didn't make sense at all, I still cann't receive any
malwares in the capture-server end. *_*!
If you know how to configure the Capture-server to
collect malwares from Capture-clients, please teach me.
Thank you very much! ^_^
-------------------------------------------------------------------
注册新浪2G免费邮箱(http://mail.sina.com.cn/)
_______________________________________________
Capture-HPC mailing list
Capture-HPC@public.honeynet.org
https://public.honeynet.org/mailman/listinfo/capture-hpc