I will provide in depth analysis for malwares and maldocs
Principle Lead ThreatOps
About this Gig
Professional Malware Analysis for Windows, Linux & Android Static & Dynamic
Facing a suspicious file or a potential breach? I provide in-depth malware analysis to help you understand the threat, contain it fast, and strengthen your defenses against future attacks.
Supported file types: EXE, DLL, ELF, APK, PDF, Word, Excel, PowerPoint, OneNote, and more.
Static Analysis
Fast, safe first-pass analysis that helps identify:
Malware type and family
Likely origin and attribution clues
Core functionality and intent
APIs used by the malware
Packed/unpacked status
Dynamic Analysis
Deeper, behavior-based analysis that reveals:
Full execution behavior in a controlled environment
De-obfuscation, decryption, and unpacking of hidden code
Concealed or delayed functionalities
C2 communication and data exfiltration attempts
Actionable detection rules/signatures (YARA) for faster future detection
Why work with me:
Faster threat detection clear IOCs and behavioral indicators you can act on immediately
Stronger security posture findings you can feed directly into your SIEM, EDR, or firewall rules
Reduced risk exposure understand exactly wha
FAQ
Is it safe to send you a suspicious file?
Yes. I analyze all files in an isolated, controlled environment, so there's no risk to your systems. I only need the file (or a safe link to it) and any context you have (where it came from, what triggered suspicion, etc.).
I'm not technical — will I understand the report?
Yes. Every report includes a plain-language summary of what the malware does and what it means for you, in addition to the technical details for your IT/security team.
What if the file turns out to be clean (not malware)?
You'll still get a full report confirming it's safe, along with the analysis steps taken to reach that conclusion — useful for peace of mind or compliance documentation.
What analysis environment/tools do you use?
A combination of static analysis tools (PE/ELF/APK parsers, disassemblers like IDA/Ghidra) and isolated dynamic analysis (sandboxed VMs) depending on the file type and platform.
Can you analyze obfuscated or packed malware?
Yes. Unpacking, de-obfuscation, and decryption of hidden payloads are part of the dynamic analysis process.
Will I get IOCs I can feed into my SIEM/EDR?
Yes. Reports include IOCs (hashes, IPs, domains, registry/file artifacts) formatted so they can be directly used in detection tooling.
Can you write custom YARA rules based on the sample?
Yes, this is included in the Premium tier and available as an add-on for other tiers.
Do you provide code review services
yes code review services are available as custom request. outside the gigs
Can you identify C2 (command & control) infrastructure?
Yes, when the sample includes network communication, dynamic analysis will capture and document C2 endpoints and exfiltration attempts.
Do you sign an NDA for sensitive incidents?
Yes, I'm open to signing an NDA for engagements involving sensitive or confidential incidents, just let me know before ordering.
