My goal is to find malware that performs network activities and captures the traffic with Wireshark. I have a Windows 10 laptop host machine and VirtualBox which has virtual Windows 10 machine.
I am scared about the safety of my host machine. How can I be safe for this type of analysis which needs an internet connection? (without internet, static analysis were easy, choose host-only adapter, take snapshots and do analysis) Should I choose "Nat network" or "Nat" or I should configure something else?
What can I do please?
– ArcherPacman Dec 26 '21 at 16:23Thank you, I checked the links but it is not clear enough for me. The malware will communicate with the internet and I will record it with Wireshark. In this case which adapter should I choose? "NAT - "NAT Network" - ? I understood that machine should be realistic, because some malware can understand if they are in VM.
– ArcherPacman Jan 05 '22 at 19:09this is good one, ok
– ArcherPacman Jan 05 '22 at 20:10