Thoughts on Triage?

Well, I came across this website known as Triage. It is a virus/malware detection website. It claims it has “a state-of-the-art malware analysis sandbox.” This website seems similar [purpose-wise] to VirusTotal or Hybrid Analysis [which are much more mainstream].

Any ideas or suggestions about this website and if its detection is on par with VirusTotal? Thank you for the help :person_bowing: .

I mean why not directly through the sources?

they dont require an account too
both have been widely used to analyze malware than triage and especially useful if you’re skeptical but not sure.

1 Like

Oh they require some email/Google/Github in the first place?
That’s putting them at the back of the queue already..

I am not sure how good they are but I would start checking their socials to figure out their street cred.
Overall, being the new kid in town doesn’t make you better. While being known by others is usual a good sign of trust, which is the most important part for this kind of service IMO.

1 Like

Yes, wrongly quoted here!

1 Like

I agree. VirusTotal and Hybrid Analysis seem to be the much better option and the most trusted analysis tools on the internet [for the average consumer].

Truthfully? You’re correct. Requiring an Email/Google/Github account seems a bit off. While the other services don’t force it in the first place..

I agree too! For as sensitive and important a service [like virus and malware scanning], it is better to opt for the community-preferred tools.

Lately, lots of products also appear out of the wild and their quality is dubious at best given how people just ship AI slop on the programming side.

Hence I would indeed just skip the entire marketing claims if they are not backed by actual expert knowledge.

I am not versed into those companies myself but a quick social stalking might give a quick clue as to what they’re pretending: are they full of BS or do they look like they know their topic well.

Just note that VirusTotal is owned by Google - but files for online malware scanning should be anyways not private (more like public programs etc.) :sweat_smile:

1 Like

I agree.
If you upload something sensitive or personal, it’s probably not a good idea.
Hence, it’s more of a public security scan than anything else.
And at the same time, there is no way that you do have the scanner being FOSS because that defeats the entire business model of such thing. :sweat_smile:

And even if it was, it is still just analytics, hence probably just as bad as a regular Antivirus scan (can be bypassed by someone talented enough).

This is how I picture a FOSS scanning tool on the client-side haha

alaynagifs

1 Like

Well, that is true. Yet, would you mind providing information on what makes VirusTotal, and Hybrid Analysis the much better option for analysis [if we exclude community feedback].

As said above

I am not versed into those companies myself

Hence I am not the right person to vouch for their quality.

I just know or see people on the Internet and sometimes read their content.
For example, I do see Troy talking and sharing security topics sometimes.
He looks very knowledgeable and recognized by other security communities, I myself have no clue if he’s as good as he looks because this is not my field of expertise.

Yet, I do think that given enough popularity in that domain and being referenced by known articles is a good enough voucher as of how good he (probably) is.

Same here, I heard the other 2 names online (on this forum and elsewhere) but I am not qualified to vouch for their trustworthiness in itself.

I’d say that going through a 3rd party security company (and having a thorough relevant report) is still the best to “prove” that a service/product is of high quality. But I am not sure how a company could “self-review” themselves. Probably ask a peer but again, that costs money and people probably don’t want others to review their review tool. :joy:

1 Like

While it is to be noted that Google is one of those data-hoarder companies, I still believe their security system to be very sophisticated and better at analyzing any given data.

Google is definitely very good at security.
Not sure if they do focus heavily on those topics as a whole or if they do delegate the work to some company that they may have bought (or developed their own tools) but the privacy topic is another topic altogether.

I do also think that Apple does a decent job with their App store apps review process, it’s probably quite precise and good yet not very private.

2 Likes