Spectra Assure Free Trial
Get your 14-day free trial of Spectra Assure for Software Supply Chain Security
Get Free TrialMore about Spectra Assure Free TrialRecursive unpacking is the process of extracting and analyzing nested files, archives, and compressed containers within a software artifact to reveal all embedded components. It’s essential for identifying deeply buried code, dependencies, or threats that are not visible through surface-level inspection.
Threat actors often hide malware or unauthorized files within multi-layered packaging formats (e.g., ZIP files within JAR files within EXE files). Without recursive unpacking, security tools may overlook critical payloads or vulnerable components embedded deep within software artifacts, especially in compiled or packaged releases.
A recursive unpacking engine:
It’s used in conjunction with binary analysis tools, malware detection engines, and Software Bill of Materials (SBOM) extractors.
Topic | Focus Area | Key Differences |
|---|---|---|
Binary SBOM | List of components in compiled code | Recursive unpacking helps generate accurate binary SBOMs |
Post-Compilation Scanning | Scans compiled artifacts | Recursive unpacking is often a prerequisite for effective scanning |
Artifact Behavioral Analysis | Runtime execution analysis | Focuses on behavior, not file structure or embedded content |

SVGs are difficult to detect, can be snuck into content — and can do malicious and legitimate actions. Here's how malicious SVGs work.

One of the most effective attack methods I've analyzed this year runs on legitimate tools and willing users — and AV and EDR is blind to it.

Threat Advisor could help teams with AI-specific risks. But a broader AppSec strategy rethink is needed in the AI era.