Controlled C2 interaction · Private preview

Exercise native post-connection behavior. Without live attacker infrastructure.

Proofmetry recreates the server-side C2 interaction a supported malware variant expects. Choose a predefined behavior test, run the customer-held sample in your lab, and use your existing tools to capture the resulting host and network activity.

Built for authorized malware labs Private preview for U.S.-based detection, research, and security data teams.
Controlled C2 interaction Customer lab
Coverage
Supported family & variant
Behavior test
Predefined
Live C2
Not required

Proofmetry platform

Recreates the server-side interaction

  • Family and variant compatibility
  • Predefined behavior tests
  • Expected host and network effects

Customer environment

Runs the customer-held sample

  • Customer-held malware
  • Customer isolation and egress controls
  • Customer-selected collection tools

The Proofmetry platform

Let supported malware perform the behavior your team needs to observe.

Proofmetry provides the server-side interaction for the selected behavior test. The customer-held sample performs the behavior, and your tools capture the endpoint and network effects.

Proofmetry

Provides the controlled C2 interaction

  1. 01
    Variant-specific interactionServer-side interaction matched to supported families and variants
  2. 02
    Behavior testsOnly behaviors included in current coverage are available
  3. 03
    Test contextVariant, selected behavior, and expected native effects
  4. 04
    Expected observationsHost and network activity to compare with customer records
Customer lab

Controls execution and collection

  1. 01
    Malware sampleCustomer-supplied and retained inside the testing environment
  2. 02
    Isolated labDisposable systems and customer-enforced network boundaries
  3. 03
    InstrumentationAPI tracing, command logging, ETW, packet capture, sandbox, EDR, or other lab tools
  4. 04
    Evaluation workflowDetection logic, labels, model artifacts, and success criteria

Your tools remain the system of record. Proofmetry does not include a telemetry recorder; your team controls telemetry, labels, and evaluation results.

How it works

From a detection or data question to observable malware behavior.

Start with the behavior your team needs to see, then confirm that the customer-held sample matches current coverage.

  1. Define the objective

    Name the detection gap, data requirement, or coverage question.

  2. Confirm compatibility

    Match the customer-held sample to a supported family and variant.

  3. Ready the lab

    Confirm authorization, containment, egress controls, and collection tools.

  4. Run the behavior test

    Proofmetry provides the controlled interaction; the customer-held sample performs the selected behavior.

  5. Review the evidence

    Compare customer-collected records with alerts, rules, labels, and expected behavior.

Family example01

C2Looper

Eight command handlers mapped. Seven paths observed in the lab.

Static analysis mapped eight command handlers in one DLL variant; seven handler paths were observed during isolated execution. Directory enumeration remained static-only. Analyst-operated research tools captured discovery, file, process, memory, and network activity from the analyzed sample without contacting GitHub or attacker-controlled infrastructure.

  • Discovery
  • File activity
  • Process activity
  • Local memory
  • Network

Why this exists

The sample remains. Its original tasking service may not.

Static analysis can reveal a capability, while attack simulation approximates behavior with a substitute. Proofmetry takes a different path: it lets the supported malware sample perform its own post-C2 behavior so your sensors can observe the native implementation.

  1. 01

    The C2 no longer works

    It may be dormant, seized, inaccessible, or unsafe to contact while the sample continues to poll.

  2. 02

    Native behavior stays out of reach

    The endpoint and network activity needed for rule testing remains behind a missing command path.

  3. 03

    Your stack keeps changing

    New sensors, parsers, rules, and model versions create new questions about what the lab will capture.

Rules and datasets

Test detections and build behavior-labeled data from the customer-held sample.

Your tools collect the telemetry. Proofmetry identifies the supported variant, selected behavior test, and expected observations so your team can interpret and label each run.

01

Detection engineering

Check whether EDR, SIEM, Sigma-derived, Snort, or Suricata detections fire—and whether the resulting records are useful for investigation.

02

Security data science

Use the sample identity, selected test, time window, and observed outcome to label telemetry from your own tools for feature development, holdout testing, and model regression.

Scope matters. The data describes one sample, one environment, and its sensors. It is not a balanced corpus, and Proofmetry does not claim that it represents every infection or improves model performance.

Threat Packs

Versioned coverage for supported malware families and variants.

A Threat Pack is a versioned coverage definition for a malware family and its supported variants. It identifies compatible sample identifiers, available behavior tests, expected observations, and known limitations so customers can confirm whether their own samples match.

  1. 01
    Supported variantsFamilies, versions, and sample identifiers
  2. 02
    Behavior testsPredefined actions available in current coverage
  3. 03
    Expected observationsHost and network activity to look for
  4. 04
    Version historyScope and changes by release

Security & trust

Designed for customer-controlled malware labs.

Proofmetry is not a public execution service and this site does not accept sample uploads. Supported tests do not require live attacker infrastructure. Customers retain control of authorization, sample handling, isolation, egress, execution, and telemetry.

Review security & trust
  • 01
    Defined testsOperators choose supported actions; there is no unrestricted tasking.
  • 02
    Customer-held samplesProofmetry does not supply malware to customers or accept public uploads.
  • 03
    No live attacker dependencySupported tests do not require contact with original C2 infrastructure.
  • 04
    Customer-enforced containmentThe customer controls isolation, egress, execution, and collection.
Built for
  • Detection engineering
  • Network detection
  • Threat research
  • Security data science
  • Purple teams and cyber ranges

Private preview

See whether current coverage matches your testing objective.

Share your work contact details. In the follow-up, we’ll discuss the malware family or sample hash, behavior test, and evidence your tools need to capture.

Get a demo U.S.-based organizations · Business email required