Important notice: BSides Curitiba 2026 · October 17 · PUCPR · Get your ticket
← All services// Services · Analysis

Malware Reverse Engineering

We analyze and reverse engineer malware to identify the origin of the attack, the behavior of the malicious code and the indicators of compromise.

// What it is

What it is about

Reverse engineering is the analysis of a finished program to understand how it works inside. In malware, it reveals what the code does, where it came from, how it spreads and how to detect it.

We have reverse engineered ransomware such as STOP/DJVU and REvil. In some cases, the analysis shows flaws in the malicious code itself that help in recovery.

// When to hire

When it makes sense

  • When a suspicious file or program has been found in the environment.
  • During a ransomware incident, to understand the family and the recovery options.
  • To generate indicators and detection rules for your defense.
// How we do it

From first contact to delivery

A predictable flow, under NDA, with the client informed at every step.

01

Agreement and scope

Bilateral NDA and proposal with scope, rules of engagement and windows defined in writing. Nothing starts without authorization.

02

Static and dynamic analysis

Study of the code and controlled execution in an isolated environment, to observe the behavior without risk to your environment.

03

Indicators

Extraction of indicators of compromise: files, domains, addresses and techniques used by the attacker.

04

Reporting

Description of how the malware works, of its impact and of the detection and removal measures.

// Deliverables

What you get

  • Technical report on the behavior of the malware.
  • Indicators of compromise ready for your defense.
  • Detection, containment and removal recommendations.

Every engagement starts with a bilateral NDA. We do not disclose client names, vulnerabilities or incidents without written authorization, and sensitive communication uses encrypted channels (Signal and PGP).

// Related services

You may also like

Incidents

Incident Management

When the attack happens, we move fast: containment, eradication, recovery and a full forensic report of the incident.

See the service
Forensics

Digital Forensics

Technical investigation of cyber incidents to determine how the attack happened, collect evidence and support legal action.

See the service
Offensive

Red Team Operations

Complete APT attack simulations, with social engineering and physical and digital intrusion, to assess your organization's real resilience.

See the service
// Ready to act?

Let's protect what is yours.

Fast response, total confidentiality and field execution. No fluff.

Cookies and privacy

NecessaryAlways on
Metrics