The original malware performs the behavior.
Proofmetry does not replace a supported sample with a generic behavior simulator. It reconstructs the interaction needed for the original implementation to run in a controlled customer lab.
About Proofmetry
Proofmetry is a malware research and validation project focused on recovering native behavior hidden behind unavailable C2 tasking. Platform access is coordinated directly through a guided evaluation process.
The focus
Malware research can reveal what a sample appears able to do. Proofmetry continues the work: recover the expected tasking or configuration, reach selected native paths, and state exactly what the resulting evidence supports.
Proofmetry does not replace a supported sample with a generic behavior simulator. It reconstructs the interaction needed for the original implementation to run in a controlled customer lab.
Static mapping, path reach, returned results, terminal states, and confirmed effects are kept distinct so research findings do not become broader product claims.
Areas of work
Variant-level analysis of dispatchers, state, behavior paths, and observable effects.
Process, file, memory, system, desktop, and lifecycle behavior at the endpoint.
Controlled recovery of the tasking or configuration a supported sample expects.
Connecting native activity to records produced by customer-operated endpoint and network sensors.
Documenting mapped, reached, observed, terminal, and confirmed evidence without collapsing the distinctions.
Guided evaluation