Agreement and scope
Bilateral NDA and proposal with scope, rules of engagement and windows defined in writing. Nothing starts without authorization.
We analyze and reverse engineer malware to identify the origin of the attack, the behavior of the malicious code and the indicators of compromise.
Reverse engineering is the analysis of a finished program to understand how it works inside. In malware, it reveals what the code does, where it came from, how it spreads and how to detect it.
We have reverse engineered ransomware such as STOP/DJVU and REvil. In some cases, the analysis shows flaws in the malicious code itself that help in recovery.
A predictable flow, under NDA, with the client informed at every step.
Bilateral NDA and proposal with scope, rules of engagement and windows defined in writing. Nothing starts without authorization.
Study of the code and controlled execution in an isolated environment, to observe the behavior without risk to your environment.
Extraction of indicators of compromise: files, domains, addresses and techniques used by the attacker.
Description of how the malware works, of its impact and of the detection and removal measures.
Every engagement starts with a bilateral NDA. We do not disclose client names, vulnerabilities or incidents without written authorization, and sensitive communication uses encrypted channels (Signal and PGP).
When the attack happens, we move fast: containment, eradication, recovery and a full forensic report of the incident.
See the serviceTechnical investigation of cyber incidents to determine how the attack happened, collect evidence and support legal action.
See the serviceComplete APT attack simulations, with social engineering and physical and digital intrusion, to assess your organization's real resilience.
See the serviceFast response, total confidentiality and field execution. No fluff.