Hybrid Sandboxing technology for Malware Analysis
Norman Shark Malware Analyzer G2 takes malware analysis to the next level with our unique hybrid malware sandboxing model.
Norman Shark delivers unmatched threat intelligence by integrating the latest virtualization technology with the award-winning Norman Shark malware sandbox. This powerful dual-detection approach combines the benefits of code emulation with virtual machine introspection to capture more malicious behavior across a wider range of custom environments than competing solutions that typically rely on a single methodology.
Norman Shark SandBox – Powerful Emulation
Norman Shark pioneered SandBoxing technology, an emulated Windows operating system environment where suspicious samples are run in simulation and examined for malicious behavior. Files execute within the simulator as they would on a real system, but no code ever executes on the targeted CPU, loads into real memory, or communicates with any other physical system components.
Malware samples infect virtual systems inside the SandBox, create and delete files, replicate, connect to carefully controlled IRC servers and URLs, send emails, set up listening ports, or perform most other functions as they would on real systems. Working at the kernel level, the emulator exercises the malware, intercepting behavior and converting it into step-by-step forensic intelligence, providing a map of the damage the threat would cause if allowed to run on a real machine, without ever putting actual systems at risk.
IntelliVM – Intelligent Virtual Machines
A virtual machine (VM) is a software implementation of a computer system that executes programs just like a physical machine, but without putting the physical machine at risk of malware infection. By using virtual machine profiles to mirror alternative types of environments, analysts can quickly spot anomalies and differences in behavior that unveil anti-analysis and other advanced malware evasion techniques.
Norman Shark’s IntelliVM technology monitors a wide range of system events for signs of malicious behavior in a safe, instrumented virtualized Windows system environment. IntelliVM profiles can be customized to add flexibility to analyze non-traditional malware and to precisely mirror custom productions environments to detect advanced and targeted threats. Security analysts can analyze any threat type, in any version of any application they choose, and can precisely match their organizations’ desktop environments, gathering intelligence on malware targeting their specific organizations which may be looking to exploit specific application vulnerabilities.
KernelScout Technology
IntelliVM uses Norman Shark’s KernelScout driver, embedding the intelligence observation agent at the lowest level of the system’s kernel. This technology offers several benefits over traditional monitoring techniques, including:
- Unrivaled transparency into all critical system events
- Superior accuracy of observed intelligence to guide remediation efforts
- Faster behavior monitoring to accelerate analysis processes
- Generates more intelligence by embedding detection at the lowest level
- Avoids detection by common anti-analysis malware techniques
- Security against malicious behavior seeking to compromise analysis labs
- Advanced rootkit monitoring

