Skip to main content
3 TO 7 DAYS

Malware Analysis

Find out exactly what that binary does

Analysis establishes what a sample actually does rather than what a vendor label claims. Static analysis of the binary is combined with instrumented dynamic execution in an isolated environment, working through packing, obfuscation, and anti-analysis techniques where present. The output is written to be actionable: not just a description, but detection rules and indicators you can deploy immediately.

When you need this

  • An unknown executable was found on a machine and nobody can say what it does
  • Your EDR flagged something and you need to know whether it was real
  • You need to know whether a sample steals data, encrypts files, or opens a backdoor
  • You want detection rules for something your vendor has not covered yet

What is included

Static analysis

PE structure, imports, embedded strings and resources, and disassembly without executing the sample.

Dynamic analysis

Instrumented detonation in an isolated lab to capture filesystem, registry, process, and network behaviour.

Unpacking and deobfuscation

Recovery of the real payload from packed, encrypted, or obfuscated samples.

Capability assessment

A clear determination of what the sample does: persistence, credential theft, encryption, or command and control.

Detection engineering

YARA rules and network indicators built from the analysis and ready to deploy.

How the engagement runs

01

Intake

Secure sample handoff and confirmation of how and where it was found.

02

Static analysis

Examination of the binary without execution, including unpacking where needed.

03

Dynamic analysis

Instrumented detonation in an isolated environment to observe real behaviour.

04

Detection

IOC extraction and YARA rule authoring, delivered with the written analysis.

What you receive

  • Malware analysis report covering behaviour and capability
  • Indicators of compromise (hashes, domains, IPs, mutexes, registry keys)
  • YARA detection rules
  • MITRE ATT&CK technique mapping
  • Containment and remediation recommendations

Tooling

IDA ProGhidrax64dbgWinDbgYARAWiresharkAny.runPEStudio

Common questions

How do we send you a sample safely?

Samples are transferred in a password-protected archive over an agreed channel, with the password sent separately. Never email a live sample unprotected, and never upload a sample containing your own sensitive data to a public sandbox, since public submissions are frequently visible to other researchers.

Can you tell us whether data was actually stolen?

Analysis establishes whether the sample has the capability to exfiltrate data, what it targets, and where it sends it. Confirming whether exfiltration actually occurred in your environment requires correlating that capability against your own network and endpoint telemetry, which falls under incident response rather than sample analysis. The two are often run together.

Discuss a malware analysis engagement

Scoping conversations are free and produce a fixed quote before any work begins.

Get in touch

Other services