Network Mapper v2.8.2 - Windows Antivirus Compatibility
π‘οΈ Antivirus Compatibility & Build Transparency
Windows Defender False Positive Fix
- Resolved Wacatac.B!ml detection - Modified Windows build process to avoid known triggers
- Preserved debug symbols - Windows binaries now include full debugging information for complete transparency
- Maintained performance - Linux/macOS builds still use optimized compilation
Build Transparency Features
- π Complete documentation - Added `BUILD_TRANSPARENCY.md` with detailed debugging instructions
- π Full source visibility - Every network operation is documented and debuggable
- π οΈ Standard library usage - Uses Go's standard `net` package in legitimate, documented ways
- π« Zero obfuscation - No packing, compression, or symbol stripping that appears suspicious
π Technical Details
Windows Build Changes
- Before: `go build -ldflags "-X main.version=${VERSION} -s -w"`
- After: `go build -ldflags "-X main.version=${VERSION}"`
- Impact: Preserves debug symbols to avoid ML false positive patterns
Why This Works
The `-s -w` flags (strip symbols/DWARF) are known triggers for Windows Defender's machine learning detection of `Trojan:Script/Wacatac.B!ml`. By preserving debug information:
- Network operations become completely transparent to antivirus analysis
- Binary behavior matches legitimate development patterns
- Security researchers can verify all network discovery logic
π§ For Developers & Security Researchers
The transparency documentation provides complete instructions for:
- Debugging network discovery with Delve
- Inspecting symbol tables and disassembly
- Monitoring actual network calls with system tools
- Verifying legitimate behavior patterns
Installation
Download the appropriate binary for your platform:
- Linux (x64): `network-mapper-linux-amd64`
- Linux (ARM64): `network-mapper-linux-arm64`
- macOS (Intel): `network-mapper-darwin-amd64`
- macOS (Apple Silicon): `network-mapper-darwin-arm64`
- Windows (x64): `network-mapper-windows-amd64.exe` (now with enhanced compatibility)
Docker
```bash
docker pull ghcr.io/nickborgers/network-mapper:v2.8.2
docker run --rm --network host ghcr.io/nickborgers/network-mapper:v2.8.2
```
Full changelog: v2.8.1...v2.8.2