Static analysis
We read the binary without running it: unpacking, disassembly and decompilation, and recovering control flow through VM-based obfuscation.
Work
Six lines of work. Each one is scoped in writing before we start.
We do both static and runtime analysis, in real or emulated environments, with our in-house tools.
A proof of concept is a reproduction for your team, included when the rules of engagement allow it. A retest is the same questions against the build you send after fixes. Duration is set during scoping.
Method
We read the binary without running it: unpacking, disassembly and decompilation, and recovering control flow through VM-based obfuscation.
We run the sample or the build and watch it: tracing and debugging a live run, and recording how hooks, integrity checks, and manually mapped images behave.
We work on real machines when behavior depends on the hardware, and in emulated environments when we need control, repeatability, or isolation for a hostile sample.
The tooling is ours. Two of the tools are public: BinDiff and HookCheck.
Lines
Samples you send. We document the loader and what the payload does on a host. If a packer has a name the binary supports, we use it.
manual mapping VM-based obfuscationA cheat sample the owner authorizes us to hold. We document how it gets into the process and how it hides.
Your anti-cheat, on the build the owner authorizes. Integrity checks are a standing topic when the rules name them.
We try to recover control flow through VM-based obfuscation. If the product is VMProtect or Themida, we say so.
Smart contracts, the software around wallets and keys, and the malware that targets them. The full scope is on the Blockchain page.
smart contracts EVM bytecode wallet drainersThis line is the wrapper around the other five. It covers scope, written authorization, questions while you fix, and the retest.
Record
Written, from the owner, before testing starts.
The build you send. Not a live player population.
What the build caught, what it missed, and the reproduction.
The same questions against the build you send after fixes.
We only test with the owner's authorization.
We never sell cheats or bypasses.
If the owner can authorize the work, send a scoping note. The sequence is on the process page.