Skip to content

[Actualizado a 30 de septiembre de 2026]

Workflow de análisis

Reglas de seguridad del laboratorio

  • NUNCA conectes la VM de análisis a Internet real.
  • NUNCA compartas el portapapeles entre host y VM de análisis.
  • SIEMPRE toma snapshot antes de ejecutar una muestra.
  • NUNCA transfieras archivos del lab al host sin verificar.
  • ACTUALIZA el host diariamente (las VMs son el sandbox, no el host).
  • Al finalizar, SIEMPRE restaura al estado limpio entre análisis.

Detalle

1. NUNCA conectes la VM de análisis a Internet real

Dos opciones:

  1. Desconexión total

desconectada

  1. Red interna

red-interna

2. NUNCA compartas portapapeles

portapapeles

3. SIEMPRE toma snapshot antes

snapshot

4. NUNCA transfieras archivos entre el host y la mv

compartida

En Windows

  1. Iniciar la mv
  2. Restaurar snapshot "FlareVM limpio"
  3. Iniciar REMnux + INetSim
  4. Transferir muestra a FlareVM (carpeta compartida temporal)
  5. Desconectar carpeta compartida
  6. Análisis estático (sin ejecutar la muestra)
  7. Tomar snapshot pre-ejecución
  8. Ejecutar muestra con monitoring activo
  9. Capturar tráfico en REMnux
  10. Documentar hallazgos
  11. Restaurar snapshot limpio

Preparación equipo

Seguir enlace usando VAGRANT.

En AWS

AMI (Windows Flare-VM)

Seguir el manual AWS Malware Lab (Flare-VM + Apache Guacamole + Terraform) partiendo de Windows Server 2022 ya que 2025 falla.

Desactivar Windows Defender

To disable Microsoft Defender Antivirus on Windows Server 2025 via Group Policy, you must first disable Tamper Protection. Otherwise, modern Windows versions will ignore Group Policy changes made to Defender.

  1. Open Group Policy Management: 1 min. Press Win + R, type gpmc.msc for Domain Group Policy (or gpedit.msc for Local Group Policy), and press Enter.

  2. Navigate to Microsoft Defender Policy: 1 min. Navigate through the path tree: Computer Configuration → Administrative Templates → Windows Components → Microsoft Defender Antivirus.

  3. Enable 'Turn off Microsoft Defender Antivirus': 2 min. Double-click Turn off Microsoft Defender Antivirus, select Enabled, and click OK.

(Note: Setting this policy to "Enabled" turns the feature OFF).

  1. Disable Real-Time Protection (Recommended): 2 min. Navigate to the sub-folder Real-time Protection. Double-click Turn off real-time protection, select Enabled, and click OK.

  2. Apply Policy Update: 1 min. Open PowerShell or Command Prompt as Administrator and run gpupdate /force to apply the policy immediately.

To verify if the policy applied successfully, run Get-MpComputerStatus | Select-Object RealTimeProtectionEnabled in PowerShell. The result should show False.

Alternative for Windows Server

If you are installing a third-party antivirus, Windows Server supports completely removing the Defender feature. You can run the following PowerShell command as Administrator and reboot:

Uninstall-WindowsFeature -Name Windows-Defender

Crear shadow copies

En Windows Server, el concepto de "Punto de restauración" (System Restore) que existe en Windows 10/11 no viene integrado. En su lugar, el sistema utiliza Instantáneas de volumen (Shadow Copies / VSS) o las Copias de seguridad de Windows Server (Windows Server Backup).

Opción 1: Crear una Instantánea de Volumen (VSS) por GUI

Para crear una instantánea rápida de un volumen (por ejemplo, C:):

  1. Abrir Administración de discos: Presiona Win + R, escribe diskmgmt.msc y pulsa Enter.

  2. Acceder a Instantáneas: Haz clic derecho sobre el volumen (por ejemplo, C:) y selecciona Configurar Instantáneas... (Configure Shadow Copies).

  3. Habilitar y Crear Instantánea: Selecciona el volumen deseado en la lista, pulsa en Habilitar (si no está activo) y haz clic en el botón Crear ahora.

Para comprobar que se creó correctamente, revisa en la lista de "Instantáneas de este volumen" que aparezca la fecha y hora actual.

Opción 2: Crear la Instantánea desde PowerShell (Más rápido)

Puedes ejecutar el siguiente comando en PowerShell como Administrador para generar la instantánea directamente:

(Get-WmiObject -List Win32_ShadowCopy).Create("C:\", "ClientAccessible")

Para verificar que la instantánea existe, ejecuta:

vssadmin list shadows

El resultado mostrará un listado con el ID y la fecha de la instantánea generada.

Opción 3: Estado del Sistema (System State Backup)

Si lo que buscas es respaldar los archivos críticos del sistema, el Active Directory (si aplica) y el registro antes de hacer cambios profundos:

  1. Instala la característica ejecutando en PowerShell:
Install-WindowsFeature -Name Windows-Server-Backup -IncludeManagementTools

  1. Crea una copia del estado del sistema guardándola en otro volumen (por ejemplo, D:):
wbadmin start systemstatebackup -backupTarget:D: -quiet

REMnux + Flare-VM