Skip to content

Network Mapper v2.8.2 - Windows Antivirus Compatibility

Choose a tag to compare

@github-actions github-actions released this 19 Sep 01:41
· 134 commits to main since this release

πŸ›‘οΈ Antivirus Compatibility & Build Transparency

Windows Defender False Positive Fix

  • Resolved Wacatac.B!ml detection - Modified Windows build process to avoid known triggers
  • Preserved debug symbols - Windows binaries now include full debugging information for complete transparency
  • Maintained performance - Linux/macOS builds still use optimized compilation

Build Transparency Features

  • πŸ“– Complete documentation - Added `BUILD_TRANSPARENCY.md` with detailed debugging instructions
  • πŸ” Full source visibility - Every network operation is documented and debuggable
  • πŸ› οΈ Standard library usage - Uses Go's standard `net` package in legitimate, documented ways
  • 🚫 Zero obfuscation - No packing, compression, or symbol stripping that appears suspicious

πŸ“Š Technical Details

Windows Build Changes

  • Before: `go build -ldflags "-X main.version=${VERSION} -s -w"`
  • After: `go build -ldflags "-X main.version=${VERSION}"`
  • Impact: Preserves debug symbols to avoid ML false positive patterns

Why This Works

The `-s -w` flags (strip symbols/DWARF) are known triggers for Windows Defender's machine learning detection of `Trojan:Script/Wacatac.B!ml`. By preserving debug information:

  • Network operations become completely transparent to antivirus analysis
  • Binary behavior matches legitimate development patterns
  • Security researchers can verify all network discovery logic

πŸ”§ For Developers & Security Researchers

The transparency documentation provides complete instructions for:

  • Debugging network discovery with Delve
  • Inspecting symbol tables and disassembly
  • Monitoring actual network calls with system tools
  • Verifying legitimate behavior patterns

Installation

Download the appropriate binary for your platform:

  • Linux (x64): `network-mapper-linux-amd64`
  • Linux (ARM64): `network-mapper-linux-arm64`
  • macOS (Intel): `network-mapper-darwin-amd64`
  • macOS (Apple Silicon): `network-mapper-darwin-arm64`
  • Windows (x64): `network-mapper-windows-amd64.exe` (now with enhanced compatibility)

Docker

```bash
docker pull ghcr.io/nickborgers/network-mapper:v2.8.2
docker run --rm --network host ghcr.io/nickborgers/network-mapper:v2.8.2
```


Full changelog: v2.8.1...v2.8.2