[Actualizado a 30 de septiembre de 2026]
Workflow de análisis🔗
Reglas de seguridad del laboratorio🔗
- NUNCA conectes la VM de análisis a Internet real.
- NUNCA compartas el portapapeles entre host y VM de análisis.
- SIEMPRE toma snapshot antes de ejecutar una muestra.
- NUNCA transfieras archivos del lab al host sin verificar.
- ACTUALIZA el host diariamente (las VMs son el sandbox, no el host).
- Al finalizar, SIEMPRE restaura al estado limpio entre análisis.
Detalle🔗
1. NUNCA conectes la VM de análisis a Internet real🔗
Dos opciones:
- Desconexión total

- Red interna

2. NUNCA compartas portapapeles🔗

3. SIEMPRE toma snapshot antes🔗

4. NUNCA transfieras archivos entre el host y la mv🔗

En Windows🔗
- Iniciar la mv
- Restaurar snapshot "FlareVM limpio"
- Iniciar REMnux + INetSim
- Transferir muestra a FlareVM (carpeta compartida temporal)
- Desconectar carpeta compartida
- Análisis estático (sin ejecutar la muestra)
- Tomar snapshot pre-ejecución
- Ejecutar muestra con monitoring activo
- Capturar tráfico en REMnux
- Documentar hallazgos
- Restaurar snapshot limpio
Preparación equipo🔗
Seguir enlace usando VAGRANT.
En AWS🔗
AMI (Windows Flare-VM)🔗
Seguir el manual AWS Malware Lab (Flare-VM + Apache Guacamole + Terraform) partiendo de Windows Server 2022 ya que 2025 falla.
Desactivar Windows Defender🔗
To disable Microsoft Defender Antivirus on Windows Server 2025 via Group Policy, you must first disable Tamper Protection. Otherwise, modern Windows versions will ignore Group Policy changes made to Defender.
-
Open Group Policy Management: 1 min. Press
Win + R, typegpmc.mscfor Domain Group Policy (orgpedit.mscfor Local Group Policy), and press Enter. -
Navigate to Microsoft Defender Policy: 1 min. Navigate through the path tree:
Computer Configuration→Administrative Templates→Windows Components→Microsoft Defender Antivirus. -
Enable 'Turn off Microsoft Defender Antivirus': 2 min. Double-click Turn off Microsoft Defender Antivirus, select Enabled, and click OK.
(Note: Setting this policy to "Enabled" turns the feature OFF).
-
Disable Real-Time Protection (Recommended): 2 min. Navigate to the sub-folder Real-time Protection. Double-click Turn off real-time protection, select Enabled, and click OK.
-
Apply Policy Update: 1 min. Open PowerShell or Command Prompt as Administrator and run
gpupdate /forceto apply the policy immediately.
To verify if the policy applied successfully, run Get-MpComputerStatus | Select-Object RealTimeProtectionEnabled in PowerShell. The result should show False.
Alternative for Windows Server🔗
If you are installing a third-party antivirus, Windows Server supports completely removing the Defender feature. You can run the following PowerShell command as Administrator and reboot:
Uninstall-WindowsFeature -Name Windows-Defender
Crear shadow copies🔗
En Windows Server, el concepto de "Punto de restauración" (System Restore) que existe en Windows 10/11 no viene integrado. En su lugar, el sistema utiliza Instantáneas de volumen (Shadow Copies / VSS) o las Copias de seguridad de Windows Server (Windows Server Backup).
Opción 1: Crear una Instantánea de Volumen (VSS) por GUI🔗
Para crear una instantánea rápida de un volumen (por ejemplo, C:):
-
Abrir Administración de discos: Presiona
Win + R, escribediskmgmt.mscy pulsa Enter. -
Acceder a Instantáneas: Haz clic derecho sobre el volumen (por ejemplo,
C:) y selecciona Configurar Instantáneas... (Configure Shadow Copies). -
Habilitar y Crear Instantánea: Selecciona el volumen deseado en la lista, pulsa en Habilitar (si no está activo) y haz clic en el botón Crear ahora.
Para comprobar que se creó correctamente, revisa en la lista de "Instantáneas de este volumen" que aparezca la fecha y hora actual.
Opción 2: Crear la Instantánea desde PowerShell (Más rápido)🔗
Puedes ejecutar el siguiente comando en PowerShell como Administrador para generar la instantánea directamente:
(Get-WmiObject -List Win32_ShadowCopy).Create("C:\", "ClientAccessible")
Para verificar que la instantánea existe, ejecuta:
vssadmin list shadows
El resultado mostrará un listado con el ID y la fecha de la instantánea generada.
Opción 3: Estado del Sistema (System State Backup)🔗
Si lo que buscas es respaldar los archivos críticos del sistema, el Active Directory (si aplica) y el registro antes de hacer cambios profundos:
- Instala la característica ejecutando en PowerShell:
Install-WindowsFeature -Name Windows-Server-Backup -IncludeManagementTools
- Crea una copia del estado del sistema guardándola en otro volumen (por ejemplo,
D:):
wbadmin start systemstatebackup -backupTarget:D: -quiet
REMnux + Flare-VM🔗
- Automatizado con Terraform ➡️ AWS Malware Lab (REMnux + FLARE-VM)