Use cases

Exercise post-connection malware behavior in your own lab.

Proofmetry is a customer-deployed platform for controlled C2 interaction with supported malware families and variants documented in real-world threat research. It recreates the server-side interaction each covered variant expects and offers predefined behavior tests without relying on live attacker infrastructure.

Detection and data workflows

Observe behavior from the customer-held sample itself.

Proofmetry recreates the server-side C2 interaction and offers a defined set of behavior tests. When the team runs a selected test, the customer-held sample performs the corresponding behavior and customer-operated tools capture the resulting host and network activity.

01

Evaluate detection coverage

Compare expected sample activity with alerts and records from the customer’s EDR, SIEM, network detection, sandbox, and other security tools.

02

Build customer-owned behavior-labeled data

Use the sample identity, selected behavior test, time window, and observed outcome to label endpoint, network, sandbox, and security-product telemetry from your own tools.

Customer boundary: Customers supply and retain the sample, operate the lab and telemetry tools, and control all downstream data. Proofmetry does not include a recorder or sample library.

Family overview

C2Looper

Proofmetry’s internal research on one Windows DLL informs private-preview C2Looper support. Compatibility and available behavior tests are confirmed during the demo process for each customer-held sample.

Research brief 001

Explore C2Looper behavior testing without its original tasking service.

The research workflow reached discovery, file, process, local-memory, and redirected-network behavior through the analyzed sample without contacting GitHub or attacker-controlled infrastructure.

Coverage model

Coverage grows by family and variant.

Each versioned Threat Pack identifies supported families, variants, sample identifiers, and behavior tests, along with expected observations and known limits. Protocol and product implementation details remain private.

Proofmetry platform
  • Variant-specific controlled C2 interaction
  • Predefined behavior tests
  • Expected host and network observations
  • No dependency on live attacker infrastructure
Customer lab
  • Authorized, customer-held malware samples
  • Containment and egress controls
  • Endpoint, network, sandbox, and security-product instrumentation
  • Rules, labels, retention, and evaluation decisions

Private preview

See whether current coverage fits your sample and lab.

Start with your work contact details. We’ll follow up to discuss the malware family or sample hash, behavior test, and what your workflow needs to measure.