Skip to main content

Service

Malware Analysis

Controlled static and dynamic malware analysis of suspicious binaries, scripts, droppers, and document payloads, producing usable indicators of compromise and clear behavior summaries.

What We Analyze

Coverage areas applied through manual validation and tool-assisted analysis.

  • Suspicious Windows, Linux, and macOS binaries
  • Office document and macro payloads
  • Malicious scripts (PowerShell, JavaScript, shell)
  • Loaders, droppers, and second-stage payloads
  • Persistence mechanisms and lateral movement tooling
  • Network communication and C2 patterns
  • Obfuscation and packing characteristics

Methodology

Samples are handled in an isolated environment. We pair static analysis with controlled dynamic execution to capture behavior, network indicators, and persistence techniques, mapping observed activity to MITRE ATT&CK.

Deliverables

What you receive at the close of the engagement.

  • Sample summary and classification
  • Behavior and capability writeup
  • Indicators of compromise (hashes, domains, IPs, paths)
  • MITRE ATT&CK mapping
  • Detection guidance
  • Containment and remediation recommendations

Who This Service Is For

Organizations and product teams that most commonly engage us for this assessment.

  • Suspicious executables
  • Office malware and macros
  • PowerShell and shell scripts
  • Downloaders and droppers
  • Trojans and RATs
  • Custom or targeted malware
  • Phishing payloads
  • Ransomware samples

When Organizations Typically Need This Assessment

Common moments in a product or compliance lifecycle where this assessment adds the most value.

  • A suspicious file was detected on an endpoint
  • A user reported a suspicious attachment
  • EDR flagged an unknown or unclassified binary
  • Following a confirmed intrusion, to characterize attacker tooling
  • To support detection engineering with new IoCs and TTPs
  • To determine data theft or destructive capability of a sample
  • To brief leadership on the nature of a threat
  • To support threat intelligence sharing with partners

Analysis Phases

A typical engagement moves through the following phases. Exact durations vary with scope and complexity.

  1. Intake

    Secure sample submission, chain-of-custody handling, and scoping.

  2. Authorization

    Analysis authorization and data handling terms are agreed.

  3. Static Analysis

    File triage, string and structure analysis, packing and obfuscation review.

  4. Dynamic Analysis

    Controlled execution in an isolated environment to capture behavior and network activity.

  5. Behavior Mapping

    Observed activity mapped to MITRE ATT&CK techniques.

  6. IoC Extraction

    Hashes, domains, IPs, paths, and registry keys extracted for detection.

  7. Reporting

    Sample summary, capability writeup, IoCs, and detection guidance.

  8. Detection Support

    Optional support for tuning EDR, SIEM, or NDR detections.

Example Finding

Illustrative only. Not a real client engagement. Provided to convey the level of detail included in reports.

HIGHIllustrative example

PowerShell Loader Delivering Credential-Stealing Payload

Business Impact
A macro-enabled document dropped an obfuscated PowerShell loader that fetched a second-stage binary designed to harvest browser credentials and beacon to an attacker-controlled domain, providing a foothold for further intrusion.
Recommendation
Block the identified domains and hashes, rotate exposed credentials on affected users, enforce macro restrictions and constrained language mode for PowerShell, and deploy the provided detection rules to catch similar loaders.

Frequently Asked Questions

Answers to the questions clients most often ask before engaging us for this assessment.

What types of malware can you analyze?

Windows, Linux, and macOS binaries; Office document and macro payloads; PowerShell, JavaScript, and shell scripts; loaders, droppers, and second-stage payloads.

How long does malware analysis take?

Most samples are analyzed within a few business days. Complex, obfuscated, or multi-stage payloads may require longer.

How should we submit a sample safely?

We provide secure submission instructions during scoping. Samples are handled in an isolated environment and access is restricted to the analyst.

Do you provide indicators of compromise (IoCs)?

Yes. Deliverables include hashes, network indicators (domains, IPs), file paths, registry keys, and detection guidance.

Do you map behavior to MITRE ATT&CK?

Yes. Observed behavior is mapped to MITRE ATT&CK techniques to support detection engineering and defensive planning.

Can you help write detections?

Yes. Deliverables include detection guidance, and we can support tuning of your EDR, SIEM, or NDR platforms on request.

Do you offer incident response as well?

Yes. Malware analysis is often part of a broader incident response engagement. See our DFIR service for full response support.

Do you sign NDAs?

Yes. Mutual NDAs are signed before samples or sensitive artifacts are exchanged.