Spectra Assure Free Trial
Get your 14-day free trial of Spectra Assure for Software Supply Chain Security
Get Free TrialMore about Spectra Assure Free TrialFirst, this new generation uses techniques to unpack and decompose files so that the malware exploits hidden inside are easily surfaced. By combining automated analysis techniques new tools can quickly identify, decompose, and de-obfuscate the underlying object structure (e.g. embedded executables, libraries, documents, resources, icons) and extract hundreds of threat indicators and capabilities from the files. The more advanced of these tools can even classify the threat level of the file and repair it so that only high risk files are sent for dynamic analysis and the final results are more accurate.
Remember, static analysis of the file occurs pre-execution and takes only milliseconds to complete regardless of their target OS or platform. It thus overcomes shortcomings of dynamic analysis while not being subject to traditional virtualization and sandbox evasion techniques. It is also extremely lightweight and easily scaled to process hundreds of thousands of files daily.
Another new capability of these tools is the ability to define and classify a file based on the files features (as opposed to hashing the file based on its bits). Functional similarity based classification enables a static analysis tool to recognize polymorphic malware and detect a new & unknown malware variant because it is functionally similar to known malware.
The new generation of security focused static analysis tools can help in three different security program areas. The first is as an automated detection tool utilizing its pre-execution and high speed analysis to filter through the vast unknown files coming into the network, defining their risk, identifying any malware embedded in them and sending the “files of interest” into incident response processes. Security teams gain earlier detection and identification of threats and by eliminating large numbers of good files early, reduce false positives and improving the efficiency of the investigation process. This compliments the use of Dynamic Analysis as only “files of interest” are sent to the sandbox greatly improving efficiency and the data extracted from both offers amazingly rich context.
The second use is by the internal malware investigation team to greatly accelerate their analysis processes and have a better starting point. The same fast analysis and deep contextual understanding of the malware, means an investigation team gains quick understanding of properties of the malware and can create “custom signatures and rules” to proactively search for that malware internally while upgrading detection capabilities across endpoints and networks. Targeted YARA rules integrated as part of static analysis can enable a security team to react faster than AV vendors in detecting unknown or polymorphic malware.
The third use is by threat hunting teams that can benefit from solid intelligence to decide what they are going to hunt for. They also need tools that help them hunt in multiple locations across their enterprise and search for their targets both historically and in real-time. The new generation of static analysis tools help here as well. Malware intelligence collected by the investigations teams and linked with the latest global threat intelligence provide excellent starting points to hunt from. The most advanced of the new static analysis tools include databases to store rich malware context and provide advanced search engines to pivot across large sample sets and push out multiple hunting queries across the network, SIEM or data lakes.
Today, the new generation of static analysis tools are in use by very large organizations including government agencies, financial services companies, and hi-tech companies with solid success. As the products mature, more mainstream adoption will occur and security focused static analysis will become a critical and common tool in the enterprise security toolkit.
Learn more about ReversingLabs static analysis engine, products including threat detection, malware analysis and hunting.
Explore RL's Spectra suite: Spectra Assure for software supply chain security, Spectra Detect for scalable file analysis, Spectra Analyze for malware analysis and threat hunting, and Spectra Intelligence for reputation data and intelligence.

ReversingLabs built a Spectra Analyze integration with CrowdStrike Falcon. The connector is available now as part of Spectra Analyze v9.6.0.
Here's how to use Spectra Analyze to hunt for malicious SVGs, from setting up queries and evaluations of samples to tips for investigation.
Spectra Detect is now Kubernetes-native. Spectra Analyze adds AI workflows for the agentic SOC. Here's everything that shipped.


