Malware Analysis Designed for Integration
The Malware Analyzer G2 (MAG2) was designed from the ground-up to be integrated into complex, multi-step customer workflow processes and extended security information frameworks. This unique and powerful core technology can form the basis of a third-party malware analysis platform – either as-is or enhanced with an integrator’s own value-added extensions – or it can be used to augment existing core processes and enrich existing data sets for downstream recipients.
Malware Analyzer G2 Typical Use Cases
- File Classification – Integrate MAG2 directly into back-end processes to make good/suspicious/bad file determinations.
- Intelligence Gathering – Use intelligence generated by MAG2 analysis to further strengthen proprietary value-added solutions. Uses include URL and domain blacklisting, file blacklisting, and reputation scoring, among others.
- Cloud-Based Analysis – Use MAG2 to provide a high-throughput, scalable hosted service-based malware analysis solution to end customers.
Key Features for Integrators
- Powerful Application Programming Interface (APIs)
- Highly-Customizable Virtual Machines
- Hybrid Threat analysis with IntelliVMs and Norman Shark SandBox® technology
- Malware Classification using Behavioral Patterns
- Flexible Plugin Support
- Open Architecture with Full Root Access
- Scalability
The Norman Shark Malware Analyzer G2 provides industry-leading Hybrid SandBoxing, technology that enables security teams to run suspicious artifacts through the award-winning Norman Shark SandBox®, and concurrently analyze the code in Norman Shark’s virtualized IntelliVM modules. Norman Shark’s Hybrid SandBoxing combines the traditional emulated sandbox with IntelliVM technology for comprehensive threat detection. This powerful dual-detection approach combines the benefits of code emulation with virtual machine introspection to capture more malicious behavior across a wider range of custom environments than competing solutions that typically rely on a single methodology.

