Detecting Avast CyberCapture Using Window Classes

Detecting Avast CyberCapture Using Window Classes
Introduction In this post, we’ll explore a technique to detect whether an executable is running inside Avast’s CyberCapture sandbox. By detecting the sandbox environment, a payload can alter its behavior to evade analysis and trick the antivirus into classifying the binary as safe.
Read More →