SHADOWBOX: Low-Artifact Malware Analysis

Amin Kharraz, IEEE Xplore pdf 2026-04-21T00:00:00

Abstract

Over the years, cyber crime attacks against critical services have become more sophisticated in launching lowprofile operations. However, an even more alarming trend is the increasing difficulty of collecting relevant evidence about modern cyber crimes and the involved threat actors in the early stages before significant damage is done. This issue puts defenders at a significant disadvantage, as it becomes exceedingly difficult to understand the attack details and formulate an appropriate response. Developing a robust analysis framework to collect evidence about modern threats has never been easy. One main challenge is to provide a robust trade-off between achieving sufficient visibility while leaving minimal detectable artifacts. This paper introduces SHADOWBOX, an open-source, low-artifact and portable analysis framework that can provide system-wide monitoring capabilities while satisfying contemporary checks that are used by modern malicious code. We designed multiple deployment scenarios, showing SHADOWBOXs potential in evidence gathering and threat reasoning in a real-world setting. By making SHADOWBOX and its execution trace data available to the broader research community, this work encourages further exploration in the field by reducing the engineering costs for threat analysis and building a longitudinal behavioral analysis catalog for diverse security domains.

Loading executive summary...
Loading full markdown...

Your browser does not support inline PDF viewing.

Download the PDF to view it.

Match Rate: 10.00/10 (Relevance to core cybersecurity goals)

LINK COPIED TO CLIPBOARD