Private preview · Security & trust

Controlled C2 interaction for customer-managed malware labs.

Proofmetry is a customer-deployed platform for controlled C2 interaction—not an attack simulator. It provides the server-side interaction needed to activate predefined post-connection behaviors in supported, customer-held malware documented in real-world threat research. The product is in private preview.

Platform design

Designed to activate native malware behavior—not simulate an attack.

A customer selects a predefined behavior test supported for an identified sample or compatible variant. Proofmetry provides the C2 interaction needed for the customer-held sample to perform the corresponding behavior inside the lab.

Predefined behavior tests

Operators can select only the commands and post-connection behaviors included in each supported test; arbitrary command entry is not available.

Variant-specific support

A family name alone does not establish coverage. Support is defined for an identified sample or compatible version or variant, together with available tests, expected observations, and documented limits.

Customer deployment

The intended execution environment remains under the customer’s administration. The customer supplies and retains each sample it is authorized to use.

Customer enforcement

Lab controls remain under the customer’s administration.

A supported behavior test complements, but does not replace, the customer’s safeguards. The customer determines authorization and enforces sample custody, isolation, network policy, supervision, and response procedures in its own environment.

01

Authority and sample custody

The customer verifies its authority to possess and execute the sample, obtains it through its own process, and controls handling throughout the test.

02

Isolation and network policy

The customer provisions the lab, restricts egress, blocks unintended external communication, and prevents contact with live attacker infrastructure.

03

Supervision and response

The customer names an operator, defines start and stop conditions, monitors the run, and responds to unexpected behavior under its own procedures.

Telemetry boundary

Customer-operated sensors capture and govern the telemetry.

The malware and lab generate the activity; customer-operated tools record it. Proofmetry provides the supported test definition and expected-behavior context, but it does not provide or operate endpoint or network sensors or assemble the customer’s dataset. Detection teams use their own tools to validate rules. Data teams collect and govern their own evidence, including API traces, command logs, ETW events, or packet captures where their instrumentation supports them. The customer controls access, storage, retention, labeling, and downstream use.

Operational review

Questions to resolve before a preview deployment.

During onboarding, both teams confirm the supported variant, selected behavior, and operating responsibilities. Customers retain responsibility for their own technical and legal review.

Test fit
  • Which exact family, variant, and predefined behavior are in scope?
  • What behavior and evidence should the test establish?
  • Which paths, versions, or outcomes remain outside the supported claim?
  • What would make the test unsuitable for the requested objective?
Operating boundary
  • Who has authority over the sample and lab?
  • Who administers isolation, egress, and test credentials?
  • Who supervises the run and can stop it?
  • How will unexpected behavior be handled under customer procedures?

Claim boundary

Private-preview scope is not a certification.

This page describes the intended operating model and current public boundaries for a product in private preview. It is not an independent audit, compliance attestation, or certification of Proofmetry, a customer environment, or a third-party security product.

What a run-specific result supports
  • An identified supported sample, version, or variant
  • A selected predefined post-connection test
  • Expected behavior categories and stated limitations
  • The outcome supported by the customer’s observations
What it does not establish
  • That every family variant is supported
  • That a customer environment is secure or compliant
  • That a rule or product detects every relevant behavior
  • That collected data is representative beyond the tested sample and scenario
No public execution or sample intake.

This website accepts business contact information through the demo form. It has no user accounts, sample upload, public trial environment, malware library, or interface for executing or controlling samples.

Private preview

Tell us what you need to test.

Share your name and company email. We’ll follow up to discuss the malware family or variant, the behavior you need to exercise, and the evidence your own sensors need to capture. Do not send samples, detection content, model artifacts, or telemetry.