Forensics

Malware Analysis

Static and dynamic reverse engineering of suspicious binaries.

What it is

We take the sample apart and tell you what it actually does: what it touches, what it talks to, how it persists, and what it took. The output is indicators you can hunt with across your estate, and a clear statement of the damage that sample was capable of doing.

How we do it

  1. 1

    Safe handling and triage

    The sample is contained in an isolated environment and classified before any execution.

  2. 2

    Static analysis

    Structure, strings, imports, packing and embedded resources examined without running it.

  3. 3

    Dynamic detonation

    Executed in an instrumented sandbox with file, registry, process and network activity fully recorded.

  4. 4

    Unpacking and deobfuscation

    Most real samples are packed; we unwrap the layers to reach the actual payload.

  5. 5

    Capability assessment

    What the sample can do — persistence, credential theft, lateral movement, encryption, exfiltration.

  6. 6

    IOC extraction

    Hashes, domains, addresses, mutexes, registry keys and behavioural signatures ready to deploy.

What's included

  • Combined static and dynamic analysis
  • Unpacking and deobfuscation
  • Network command-and-control identification
  • Persistence mechanism documentation
  • IOCs plus YARA and Sigma rules
  • MITRE ATT&CK technique mapping

Who needs it

  • Teams that caught something their tooling could not name
  • Incident responders needing to scope a compromise
  • Organisations wanting to know exactly what a sample was capable of

Deliverables

  • Technical analysis of the sample's behaviour
  • IOC set with YARA and Sigma rules
  • ATT&CK technique mapping
  • Hunting guidance for finding it elsewhere in your estate

Compliance relevance

NIST CSFISO 27001

Frequently asked questions

Password-protected archive over a channel we agree. Do not email it unprotected, and do not upload it to a public scanning service if the sample might be targeted at you specifically — that tips off the operator.
Initial triage and IOCs typically within 24 hours. Full analysis of a heavily obfuscated sample takes longer, and we will give you the useful indicators first rather than making you wait for the complete report.
Sometimes we can point to tooling, infrastructure or code overlap consistent with a known group. Confident attribution to a named actor usually needs more than one sample, and we will not assert it on thin evidence.
New to managed detection?

Our guide covers how SOC, MSSP, MDR and SIEM actually differ, build vs buy, and the metrics that matter.

Read the guide

Related services

Digital Forensics & IR

Forensic acquisition and analysis to reconstruct and contain incidents.

Learn More

Incident Response

Rapid containment, eradication, and recovery led by senior responders.

Learn More

Threat Hunting

Hypothesis-driven hunts surfacing threats that evade automated tooling.

Learn More