Evaluate detection coverage
Compare expected sample activity with alerts and records from the customer’s EDR, SIEM, network detection, sandbox, and other security tools.
Use cases
Proofmetry is a customer-deployed platform for controlled C2 interaction with supported malware families and variants documented in real-world threat research. It recreates the server-side interaction each covered variant expects and offers predefined behavior tests without relying on live attacker infrastructure.
Detection and data workflows
Proofmetry recreates the server-side C2 interaction and offers a defined set of behavior tests. When the team runs a selected test, the customer-held sample performs the corresponding behavior and customer-operated tools capture the resulting host and network activity.
Compare expected sample activity with alerts and records from the customer’s EDR, SIEM, network detection, sandbox, and other security tools.
Use the sample identity, selected behavior test, time window, and observed outcome to label endpoint, network, sandbox, and security-product telemetry from your own tools.
Family overview
Proofmetry’s internal research on one Windows DLL informs private-preview C2Looper support. Compatibility and available behavior tests are confirmed during the demo process for each customer-held sample.
The research workflow reached discovery, file, process, local-memory, and redirected-network behavior through the analyzed sample without contacting GitHub or attacker-controlled infrastructure.
Coverage model
Each versioned Threat Pack identifies supported families, variants, sample identifiers, and behavior tests, along with expected observations and known limits. Protocol and product implementation details remain private.
Private preview
Start with your work contact details. We’ll follow up to discuss the malware family or sample hash, behavior test, and what your workflow needs to measure.