Predefined behavior tests
Operators can select only the commands and post-connection behaviors included in each supported test; arbitrary command entry is not available.
Private preview · Security & trust
Proofmetry is a customer-deployed platform for controlled C2 interaction—not an attack simulator. It provides the server-side interaction needed to activate predefined post-connection behaviors in supported, customer-held malware documented in real-world threat research. The product is in private preview.
Platform design
A customer selects a predefined behavior test supported for an identified sample or compatible variant. Proofmetry provides the C2 interaction needed for the customer-held sample to perform the corresponding behavior inside the lab.
Operators can select only the commands and post-connection behaviors included in each supported test; arbitrary command entry is not available.
A family name alone does not establish coverage. Support is defined for an identified sample or compatible version or variant, together with available tests, expected observations, and documented limits.
The intended execution environment remains under the customer’s administration. The customer supplies and retains each sample it is authorized to use.
Customer enforcement
A supported behavior test complements, but does not replace, the customer’s safeguards. The customer determines authorization and enforces sample custody, isolation, network policy, supervision, and response procedures in its own environment.
The customer verifies its authority to possess and execute the sample, obtains it through its own process, and controls handling throughout the test.
The customer provisions the lab, restricts egress, blocks unintended external communication, and prevents contact with live attacker infrastructure.
The customer names an operator, defines start and stop conditions, monitors the run, and responds to unexpected behavior under its own procedures.
Telemetry boundary
The malware and lab generate the activity; customer-operated tools record it. Proofmetry provides the supported test definition and expected-behavior context, but it does not provide or operate endpoint or network sensors or assemble the customer’s dataset. Detection teams use their own tools to validate rules. Data teams collect and govern their own evidence, including API traces, command logs, ETW events, or packet captures where their instrumentation supports them. The customer controls access, storage, retention, labeling, and downstream use.
Operational review
During onboarding, both teams confirm the supported variant, selected behavior, and operating responsibilities. Customers retain responsibility for their own technical and legal review.
Claim boundary
This page describes the intended operating model and current public boundaries for a product in private preview. It is not an independent audit, compliance attestation, or certification of Proofmetry, a customer environment, or a third-party security product.
This website accepts business contact information through the demo form. It has no user accounts, sample upload, public trial environment, malware library, or interface for executing or controlling samples.
Private preview
Share your name and company email. We’ll follow up to discuss the malware family or variant, the behavior you need to exercise, and the evidence your own sensors need to capture. Do not send samples, detection content, model artifacts, or telemetry.