Threat Detection & Response
Malware Analysis
Understand what malicious code does, where it came from and how to stop it.
Overview
Know exactly what you're dealing with.
CDT examines malicious software to understand its behavior, functionality, origin and potential impact, and how it threatens your systems, networks and users. The result is the intelligence you need to contain it and defend against it.
What's included
Capabilities
Static and dynamic analysis
Safe detonation and code-level analysis of samples.
Indicators of compromise
Signatures and indicators to find the malware across your environment.
Capability assessment
What the malware can do, what it did, and what it targets.
How we work
A proven, repeatable process.
-
1
Triage
We establish what happened, what is at risk and what must be preserved, starting from your first call.
-
2
Contain
We stop the spread: isolating systems and accounts without destroying the evidence you will need.
-
3
Investigate
Forensic analysis of devices, networks and logs reconstructs how the attacker got in and what they touched.
-
4
Eradicate & recover
We remove the attacker's foothold and help you restore normal operations safely.
-
5
Harden & report
A clear report for leadership, counsel and regulators, and the fixes that prevent a repeat.
Related services
Often paired with
Threat Detection & Response
Incident Response & Digital Forensics
Contain the attack, preserve the evidence and restore operations, with forensics that stand up to scrutiny.
Offensive Security & Assessment
Vulnerability Research & Reverse Engineering
Deep analysis of software, firmware and hardware to uncover flaws that scanners never find.
Let's talk
Let's talk about malware analysis.
Talk with a CDT engineer about your mission, your systems and your deadlines. We'll tell you honestly what it takes.