Understand risk. Strengthen systems. Recover securely.
We reverse engineer undocumented software and firmware, analyse malware under controlled conditions, and validate security through authorised testing, code review and audits. We then help you act on what we find. Every engagement is scoped, authorised in writing and backed by evidence, for government, business and individuals.
Who we help
Choose the path that matches how you will buy or commission the work. Each route states what we can evidence today and what we will not guess at.
Our services
Six services, grouped by the decision they support. Each page states scope, exclusions, deliverables and limitations.
Strengthen
Respond & recover
Dealing with an active incident right now?
Do not upload evidence here. Get incident help for safe first actions and a verified contact route.
How we work
The public site is a front door. Analysis, reverse engineering and testing happen only after documentary authority, a written scope and a private channel, never from a file dropped on a webpage.
Authority first
Ownership or written authority for the exact target is required before reverse engineering, malware analysis or penetration testing begins. A form is not a contract.
Private by default
Suspected samples are never uploaded to public sandboxes from this practice. Transfer is arranged after scoping, over a controlled channel, off this website.
Confidence labelled
Reports separate direct observation, technical inference and recommendation. Attribution, recovery and “no other malware exists” are never over-claimed.
How an engagement works
Authorise
Confirm ownership or written authority for the exact target.
Scope
Agree what questions the work needs to answer.
Analyse or test
Controlled work against the agreed scope only.
Report and remediate
Deliver findings and practical next steps. Secure evidence transfer, where needed, is agreed after triage and authority checks, never through this website.
Case studies
Each card opens a full article. The examples below are Australian Cyber Security Centre illustrations, not MalwareAnalysis.app client engagements.
Six gift cards and a forged executive
A courier employee bought six $500 prepaid cards after mail that looked like it came from an executive. There was no malware. The missing control sat in the payment process.
More than $150,000 to a supplier who never changed banks
A construction firm paid an invoice twice after a supplier mailbox was taken over. No callback. No funds recovered.
The backup that encrypted itself
Ransomware at an auto parts store encrypted the live files and the backup disk still plugged into the same machine. Years of data went with the old system.
Recent articles
For Government & Business
What research says about trust and SEO on cybersecurity websites
Peer-reviewed findings on first-impression credibility, internal privacy assurances versus fake seals, and why YMYL-adjacent malware and reverse-engineering pages need citations, not homepage identity grids.
Read articleFor Government & Business
What ASD’s 2024–25 threat year means for six kinds of specialist work
Ransomware share held, DDoS surged, legacy technology and third-party risk are official ASD actions. How that maps to reverse engineering, malware analysis, code review, testing, audit and recovery, using ACSC, ASD and (ISC)² terms.
Read articleFor Government, Business & Individuals
Private malware analysis versus a public sandbox
When a public malware scanner is enough, when it leaks your sample, and the decision rule for commissioning private analysis instead.
Read articleReady to talk about your situation?
Tell us the high-level scope. No malware, source code or evidence – just enough for us to route you safely.