Actionable Intelligence for Malware Defense.

Products & Solutions » Solutions » Back-end Intelligence
Back-end Intelligence

Malware Analysis Designed for Integration

The Malware Analyzer G2 (MAG2) was designed from the ground-up to be integrated into complex, multi-step customer workflow processes and extended security information frameworks. This unique and powerful core technology can form the basis of a third-party malware analysis platform – either as-is or enhanced with an integrator’s own value-added extensions – or it can be used to augment existing core processes and enrich existing data sets for downstream recipients.

Malware Analyzer G2 Typical Use Cases

  1. File Classification – Integrate MAG2 directly into back-end processes to make good/suspicious/bad file determinations.
  2. Intelligence Gathering – Use intelligence generated by MAG2 analysis to further strengthen proprietary value-added solutions. Uses include URL and domain blacklisting, file blacklisting, and reputation scoring, among others.
  3. Cloud-Based Analysis – Use MAG2 to provide a high-throughput, scalable hosted service-based malware analysis solution to end customers.

 Key Features for Integrators

  • Powerful Application Programming Interface (APIs)
  • Highly-Customizable Virtual Machines
  • Hybrid Threat analysis with IntelliVMs and Norman Shark SandBox® technology
  • Malware Classification using Behavioral Patterns
  • Flexible Plugin Support
  • Open Architecture with Full Root Access
  • Scalability

The Norman Shark Malware Analyzer G2 provides industry-leading Hybrid SandBoxing, technology that enables security teams to run suspicious artifacts through the award-winning Norman Shark SandBox®, and concurrently analyze the code in Norman Shark’s virtualized IntelliVM modules. Norman Shark’s Hybrid SandBoxing combines the traditional emulated sandbox with IntelliVM technology for comprehensive threat detection. This powerful dual-detection approach combines the benefits of code emulation with virtual machine introspection to capture more malicious behavior across a wider range of custom environments than competing solutions that typically rely on a single methodology.

“In today’s climate of persistent threats, network defense alone is no longer enough. In order to protect networks from the proliferation of targeted attacks and unknown threats, analysts need dynamic malware intelligence capabilities that allow them to respond quickly in the event of an incursion.”