Services
Malware & Phishing Analysis
Joe Sandbox and ANY.RUN detonation workflows that turn a reported email into indicators, detections and a defensible verdict.
The problem we solve
A user reports a suspicious email. Without an analysis path, the answer is a guess, the verdict is inconsistent between analysts, and nothing from the investigation is fed back into detection.
How we approach it
We set up the detonation environment and the handling procedure around it: safe submission, evidence retention, and a written verdict standard so two analysts reach the same conclusion on the same sample. Indicators extracted from each case go back into the SIEM and endpoint platform, so an investigation improves detection instead of ending in a closed ticket.
What you get
- Sandbox environment configured for safe submission and retention
- Phishing triage runbook from user report to verdict
- Written verdict criteria so results are consistent between analysts
- Indicator extraction feeding SIEM and endpoint detection content
- Reporting template for stakeholders and, where needed, regulators
Platforms we use
Platform choice follows your environment. These are the ones we support hands-on in this area.
Malware Analysis
Malware Analysis (2)- Joe Sandbox
- ANY.RUN
Email Security
Email Security (3)- Avanan
- Mimecast
- Cisco IronPort
Related engagements
Ready to scope this engagement?
Tell us about your environment and we will come back with a realistic scope, sequence and effort estimate.
