Proofmetry Research

Published malware behavior research

Proofmetry research distinguishes analysis findings from execution evidence and current product support. A mapped handler is not an observed effect, and a research scenario is not automatically an available behavior test.

Publication library

Two public research briefs

Research brief 002 · Revision 1.1Published

Abyssos v2.1F

Abyssos v2.1F: from C2 tasking to endpoint evidence

One 64-bit Windows modular RAT sample, exercised through a fixed 25-scenario research matrix.

Research brief 001 · Revision 1.2Published

C2Looper

C2Looper: what seven native command paths revealed

One GitHub-C2 Windows DLL variant, with eight command handlers mapped and seven handler paths observed.

Evidence vocabulary

Proofmetry Evidence Status

Research claims use the highest level actually supported, not the highest level available in the model.

  1. 01

    Mapped

    A behavior or handler was identified through analysis.

  2. 02

    Path reached

    Execution entered the intended code path.

  3. 03

    Result observed

    A meaningful intermediate or returned result was observed.

  4. 04

    Terminal state observed

    The workflow reached a defined completion or stop condition.

  5. 05

    Endpoint effect confirmed

    The intended native endpoint or network effect was corroborated.

Guided evaluation

Connect the research to your detection and data workflows.

We confirm current variant and behavior-test fit before a customer-controlled run.

Get a demo