Actionable Intelligence for Malware Defense.

Products & Solutions » Technology » IntelliVM Profiles
IntelliVM Profiles

IntelliVM – Intelligent Virtual Machines

A virtual machine (VM) is a software implementation of a computer system that executes programs just like a physical machine, but without putting the physical machine at risk of malware infection.  By using virtual machine profiles to mirror alternative types of environments, analysts can quickly spot anomalies and differences in behavior that unveil anti-analysis and other advanced malware evasion techniques.

Norman Shark’s IntelliVM technology monitors a wide range of system events for signs of malicious behavior in a safe, instrumented virtualized Windows system environment.  IntelliVM profiles can be customized to add flexibility to analyze non-traditional malware and to precisely mirror custom productions environments to detect advanced and targeted threats.  Security analysts can analyze any threat type, in any version of any application they choose, and can precisely match their organizations’ desktop environments, gathering intelligence on malware targeting their specific organizations which may be looking to exploit specific application vulnerabilities.

IntelliVM Profiles

Supports multiple profiles for powerful analysis

  • Windows 8 (64-bit) , Windows 7 SP1 (32/64), Windows XP SP3

Customize to closely match production environments

  • Gauge threats against different areas of your enterprise
  • Pilot patches, software rollouts, and O/S upgrades
  • Test with exact application versions, browsers, add-ons, etc.

Flexibility to detect non-traditional threats

  • VM kernel and application-level event monitoring
  • Supports EXE, DLL, PDF, JAR, BAT, Office Documents (with Microsoft Office installed), commercial software, and custom applications

Plugins interact with malware before, during, and after analysis

  • Respond to dialog boxes
  • Click through installers
  • Extend custom processing
“In today’s climate of persistent threats, network defense alone is no longer enough. In order to protect networks from the proliferation of targeted attacks and unknown threats, analysts need dynamic malware intelligence capabilities that allow them to respond quickly in the event of an incursion.”