<?xml version="1.0" encoding="utf-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Recent posts to Discussion</title><link>https://sourceforge.net/p/clamsentinel/discussion/</link><description>Recent posts to Discussion</description><atom:link href="https://sourceforge.net/p/clamsentinel/discussion/feed.rss" rel="self"/><language>en</language><lastBuildDate>Sat, 27 Apr 2024 10:46:17 -0000</lastBuildDate><atom:link href="https://sourceforge.net/p/clamsentinel/discussion/feed.rss" rel="self" type="application/rss+xml"/><item><title>Goodbye To Clam Sentinel!</title><link>https://sourceforge.net/p/clamsentinel/discussion/976132/thread/7f3a2f19/?limit=25&amp;page=1#b25d</link><description>&lt;div class="markdown_content"&gt;&lt;p&gt;Goodbye ClamSentiel long live Xylent!&lt;/p&gt;&lt;/div&gt;</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">Emirhan Uçan</dc:creator><pubDate>Sat, 27 Apr 2024 10:46:17 -0000</pubDate><guid>https://sourceforge.netdd5afdd33cfe28057f8742489ff31019fadd3458</guid></item><item><title>Goodbye To Clam Sentinel!</title><link>https://sourceforge.net/p/clamsentinel/discussion/976132/thread/7f3a2f19/?limit=25&amp;page=1#5075/e72e/c3e4/35b5/3c3d/68f7/2d78/00c7/37f4/3b7e/3728/fbb2/8a2c/5800/e447/7a42/6399/374a/12a2/adc4/afcc</link><description>&lt;div class="markdown_content"&gt;&lt;p&gt;Hello Lukas:&lt;/p&gt;
&lt;p&gt;Here I am.  I relocated my signon information for Clam Sentinel forum.   Good that you are able to do something with Python&lt;/p&gt;
&lt;p&gt;For the Sentinel heuristics, the main one was the calculation of the entropy of a file.  Entropy is the measurement of the "randomness" of a file.  A file that is heavily obfuscated with other software will be very random, while a file that performs legitimate useful activities will be direct and to the point, not showing much entropy.  Maximum entropy is 7.0.  We set our entropy heuristic at 95% of maximum--6.65.  We eventually had to reduce it a bit because some malware writers caught on to this and reduced their file entropy below 95%.  Entropy is sometimes called "Shannon entropy".  &lt;/p&gt;
&lt;p&gt;We also had a few common sense heuristics--like double extensions where the first extension was .exe or some other executable extension--such as : filename.exe.txt or similar, where the exe was the extension that was executed.  Later on, Andrea added some heuristics based on examining the Windows executable file structure detail.  Another heuristic was one that looked at files placed in common folders where malware was often placed.&lt;/p&gt;
&lt;p&gt;We gave points for the heuristics and set Sentinel to quarantine a file when a certain number of points was reached.  I for get where it was set.&lt;/p&gt;
&lt;p&gt;Please let me know if there is anything I can do to help.&lt;/p&gt;
&lt;p&gt;Regards,&lt;br/&gt;
Robert&lt;/p&gt;&lt;/div&gt;</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">Robert Scroggins</dc:creator><pubDate>Sat, 02 Sep 2023 21:10:23 -0000</pubDate><guid>https://sourceforge.netae84c82399a607fde606de8c361d2386ddcbec8d</guid></item><item><title>Goodbye To Clam Sentinel!</title><link>https://sourceforge.net/p/clamsentinel/discussion/976132/thread/7f3a2f19/?limit=25&amp;page=1#5075/e72e/c3e4/35b5/3c3d/68f7/2d78/00c7/37f4/3b7e/3728/fbb2/8a2c/5800/e447/7a42/6399/374a/12a2/adc4</link><description>&lt;div class="markdown_content"&gt;&lt;p&gt;Hi Robert. I guess you're not answering my forum posts and emails haha.&lt;br/&gt;
If you read this, I would like to inform you that I managed to create a simple script in Python for the latest clamav engine. When running, it can scan with clamscan any file in the selected folder for any clamav signatures, and if so, it quarantines and encrypts it. It's not something "amazing" but I'll keep working tomorrow. I am planning to do:&lt;br/&gt;
-on-demand scanning&lt;br/&gt;
- work on mistakes&lt;br/&gt;
- create a heuristic&lt;br/&gt;
-develop a graphical interface (for now everything is in cmd ^^)&lt;br/&gt;
If you are interested in this or would like help with testing, please contact us.&lt;br/&gt;
Greetings ;)&lt;/p&gt;&lt;/div&gt;</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">Lukas </dc:creator><pubDate>Sat, 02 Sep 2023 01:18:34 -0000</pubDate><guid>https://sourceforge.net9e89cf35437c31ab7b0058a6dea6243b30402483</guid></item><item><title>Goodbye To Clam Sentinel!</title><link>https://sourceforge.net/p/clamsentinel/discussion/976132/thread/7f3a2f19/?limit=25&amp;page=1#5075/e72e/c3e4/35b5/3c3d/68f7/2d78/00c7/37f4/3b7e/3728/fbb2/8a2c/5800/e447/7a42/6399/374a/12a2/53f1</link><description>&lt;div class="markdown_content"&gt;&lt;p&gt;Hi Robert, I don't know if you read but I sent you an email with a link to download 7z. Let me know when it arrived.&lt;/p&gt;&lt;/div&gt;</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">Robert Scroggins</dc:creator><pubDate>Fri, 01 Sep 2023 14:00:18 -0000</pubDate><guid>https://sourceforge.nete399cb93b644fc7aec3497128595d2184873029e</guid></item><item><title>Goodbye To Clam Sentinel!</title><link>https://sourceforge.net/p/clamsentinel/discussion/976132/thread/7f3a2f19/?limit=25#5075/e72e/c3e4/35b5/3c3d/68f7/2d78/00c7/37f4/3b7e/3728/fbb2/8a2c/5800/e447/7a42/6399/374a/12a2/2bbf</link><description>&lt;div class="markdown_content"&gt;&lt;p&gt;Robert, unfortunately google doesn't allow you to send any zip archives, 7zip etc...&lt;br/&gt;
Could you download the file via torrent? I'd give you a signature to create a file and download it directly from me. qBittorent is good&lt;/p&gt;&lt;/div&gt;</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">Lukas </dc:creator><pubDate>Thu, 31 Aug 2023 20:04:48 -0000</pubDate><guid>https://sourceforge.net3e4297e190774f803637620f647a7bc400c92729</guid></item><item><title>Goodbye To Clam Sentinel!</title><link>https://sourceforge.net/p/clamsentinel/discussion/976132/thread/7f3a2f19/?limit=25#5075/e72e/c3e4/35b5/3c3d/68f7/2d78/00c7/37f4/3b7e/3728/fbb2/8a2c/5800/e447/7a42/6399/edb7</link><description>&lt;div class="markdown_content"&gt;&lt;p&gt;Robert, the problem is I can't email you. I got a return from my server that you have some kind of block.&lt;/p&gt;&lt;/div&gt;</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">Lukas </dc:creator><pubDate>Thu, 31 Aug 2023 16:46:45 -0000</pubDate><guid>https://sourceforge.netd87b174b2579c786025329b1e990965acb9b3272</guid></item><item><title>Goodbye To Clam Sentinel!</title><link>https://sourceforge.net/p/clamsentinel/discussion/976132/thread/7f3a2f19/?limit=25#5075/e72e/c3e4/35b5/3c3d/68f7/2d78/00c7/37f4/3b7e/3728/fbb2/8a2c/5800/e447/7a42/6399/374a</link><description>&lt;div class="markdown_content"&gt;&lt;p&gt;Robert, the problem is I can't email you. I got a return from my server that you have some kind of block.&lt;/p&gt;&lt;/div&gt;</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">Lukas </dc:creator><pubDate>Thu, 31 Aug 2023 15:06:14 -0000</pubDate><guid>https://sourceforge.net94b5b2514f7423ff34d935c6ef0cd5bbb18abe1f</guid></item><item><title>Goodbye To Clam Sentinel!</title><link>https://sourceforge.net/p/clamsentinel/discussion/976132/thread/7f3a2f19/?limit=25#5075/e72e/c3e4/35b5/3c3d/68f7/2d78/00c7/37f4/3b7e/3728/fbb2/8a2c/5800/e447/7a42</link><description>&lt;div class="markdown_content"&gt;&lt;p&gt;The sentinental source code is only 3Mb, and 500kb when compressed. Believe me, I could telegram it to you haha.&lt;br/&gt;
I will email you future messages so as not to clutter the forum or if you prefer we can use something like bitmessage&lt;/p&gt;&lt;/div&gt;</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">Lukas </dc:creator><pubDate>Thu, 31 Aug 2023 14:17:48 -0000</pubDate><guid>https://sourceforge.netc9529d4b191a53fb408e46f8e2e64becd1fb59c9</guid></item><item><title>Goodbye To Clam Sentinel!</title><link>https://sourceforge.net/p/clamsentinel/discussion/976132/thread/7f3a2f19/?limit=25#5075/e72e/c3e4/35b5/3c3d/68f7/2d78/00c7/37f4/3b7e/3728/fbb2/8a2c/5800/b9c7/cdad</link><description>&lt;div class="markdown_content"&gt;&lt;p&gt;I don't know if you mean the Clam Senintel.conf file in %appdata% which has a section Path =&lt;br/&gt;
3 - all on&lt;br/&gt;
2 - sentinel portable&lt;br/&gt;
1 - heu only&lt;/p&gt;&lt;/div&gt;</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">Lukas </dc:creator><pubDate>Thu, 31 Aug 2023 14:15:03 -0000</pubDate><guid>https://sourceforge.net6e0ef13c2e5e6e925c4e6f6c94be81e7a65df454</guid></item><item><title>Goodbye To Clam Sentinel!</title><link>https://sourceforge.net/p/clamsentinel/discussion/976132/thread/7f3a2f19/?limit=25#5075/e72e/c3e4/35b5/3c3d/68f7/2d78/00c7/37f4/3b7e/3728/fbb2/8a2c/5800</link><description>&lt;div class="markdown_content"&gt;&lt;p&gt;Hi robert. I wish you had received my message two weeks ago. It seems to show me that it is waiting for moderator verification.&lt;br/&gt;
Coming back, I'd be happy to send you the source code. Tell me what you would like, email, torrent or maybe something else. I'm open.&lt;/p&gt;
&lt;p&gt;As for CS and CW itself, I'm a very basic programmer and I can't tell you much about it. I agree that it is possible to disable CS heuristics (which is more difficult) and disable CW scanning (easier).&lt;br/&gt;
Clam Sentinel works in such a way that it reads what is written in the .conf of CW, which means that it is heavily dependent on it. In .conf CW you can change the default ClamAV engine files 'freshclam.exe' and 'clamscan.exe' or paste them manually in the installation folder + some libraries. The problem is that clamin is not just a frontend and it reads different versions of clamav differently. ClamAV has also changed over several versions.&lt;br/&gt;
There is currently no problem with signature scanning as clamav version 0.103.2.1 supports downloads *for now.&lt;br/&gt;
The problem is that it's been two years since the clamav engine was last integrated into clamwin, and the newer engine after the first one is more optimized, segregates signatures differently and has major vulnerabilities patched.&lt;br/&gt;
From what I've looked at sentinental's code, it's more 'simple' than CW, hah&lt;br/&gt;
Python is a fairly easy language. I'll try to mess something up.&lt;/p&gt;
&lt;p&gt;My dream was to release CS 1.23 on github :)&lt;/p&gt;&lt;/div&gt;</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">Lukas </dc:creator><pubDate>Thu, 31 Aug 2023 13:39:52 -0000</pubDate><guid>https://sourceforge.netdafa5b6ae5929ff196634dd8d1bb9a9fc4571f40</guid></item></channel></rss>