Lab-grade reverse engineering.
Our analysts work in isolated detonation environments with full instrumentation. Static analysis in Ghidra and IDA Pro maps capabilities without execution; dynamic analysis watches the sample behave — C2, persistence, lateral movement, exfiltration.
- Full capability mapping — what the sample can do, what it actually did in your environment, and what it tried next.
- IOC packages — hashes, domains, IPs, mutexes, and YARA/Sigma rules tuned for your SIEM and EDR.
- Safe handling — chain-of-custody sample intake, air-gapped detonation, and certified destruction on request.
What’s included
From sample to detection in days.
Triage
24-hour initial verdict
Malicious or benign, with confidence level and immediate containment guidance — before the full teardown completes.
Deep dive
Behavioral teardown report
Execution flow, persistence mechanisms, C2 protocol, and data-access patterns documented for your responders.
Defend
Detection engineering
YARA, Sigma, and EDR hunting queries written against the sample’s actual behavior — tested, not templated.
Engagement flow
Submit a sample, get answers.
Upload through our encrypted intake with context on where the sample was found. Triage lands within one business day; full teardowns typically complete within a week, with interim IOCs as they’re confirmed.
What sample types do you accept? +
Executables, scripts, weaponized documents, browser artifacts, mobile APKs/IPAs, firmware images, and memory dumps. If it runs somewhere, we can analyze it.
Is my data kept confidential? +
Strictly. Samples are handled under NDA with access-limited storage, and we never submit client samples to public sandboxes or share IOCs without permission.
Can you help with attribution? +
We provide TTP mapping to MITRE ATT&CK and overlap analysis with known tooling — assessed confidence levels included, speculation excluded.
Submit a sample for analysis.
Related: Threat Hunting · Incident Response · Our tooling