How a National Cybersecurity Provider Builds Proprietary Threat Intelligence on Its Own Terms

Customer Story

Introduction

In a region investing heavily in its own cybersecurity capability, one organization sits at the center of that ambition. A major national cybersecurity services provider, that exists to develop and strengthen the security industry across its country, supporting national resilience through a broad portfolio of managed services.

Its remit is wide. Across an organization of several hundred people, dedicated teams deliver managed detection and response, incident response, vulnerability assessment, governance and compliance, and at the core of its intelligence work, a specialized cyber threat intelligence team. That CTI team runs brand monitoring, attack surface management, and a full spectrum of intelligence reporting, from adversary profiles and malware analysis to campaign tracking and machine-readable threat feeds.

For a provider operating at this level, threat intelligence has to be something you diligently build yourself.


The Challenge: Producing Intelligence No One Else Can

The team set a high bar for itself. Commercial threat feeds have their place, but they are available to everyone, which limits how much advantage they can offer. The most valuable intelligence is the intelligence an organization produces itself, derived from its own analysis, its own samples, and a level of access that no external provider can replicate.

Building that capability brought a clear set of requirements.

  • The samples the team handles are sensitive. Much of the most valuable analysis involves material that cannot leave their environment, which ruled out any approach dependent on cloud-only analysis.

  • At the same time, the team needed depth and scale. They gather large and growing volumes of samples, both from their own collection efforts and from real incident engagements, and they needed to extract maximum structured value from each one: indicators, behaviors, configurations, and the evidence behind every verdict. Generic detection was never going to be enough. When you publish intelligence that other organizations act on, you have to be able to explain precisely why a sample was flagged.

  • And all of it had to integrate. The team operates its own pipelines and threat intelligence platforms, and any analysis engine had to feed those systems cleanly, in the formats their downstream consumers expect.


The Solution: A Deep Analysis Engine, Fully Under Their Control

The team integrated VMRay as the analysis engine behind their intelligence operation, deployed on-premises and entirely within their own environment.

The on-premises deployment was decisive. It gave the team complete control over their data with no compromise in capability, the same depth of analysis available in the cloud, running on their own infrastructure. For an organization whose most sensitive work cannot leave its walls, that parity matters.

From there, they made VMRay their own. The team plugged their proprietary reputation engine directly into the platform and integrated their internally developed YARA rules, combining VMRay’s analysis depth with their own intelligence assets. Rather than using the platform as a closed box, they built it into the center of their workflow.

That workflow is highly automated. The team runs a pipeline that submits sample sets to VMRay at scale, analyzes which YARA rules trigger on which files, and extracts the indicators that matter, IP addresses, filenames, dropped files, and more. Alongside this automated pipeline, analysts use VMRay for ad hoc malware analysis during incident engagements, enriching what they observe in the field.

Throughout, two capabilities proved especially valuable: malware configuration extraction, which surfaces the operational details of a threat, and the transparency behind every verdict, which lets analysts understand the specific factors that contributed to a sample being marked malicious.


The Impact: Proprietary Intelligence, Delivered with Confidence

With VMRay embedded in their operation, the team produces intelligence that commercial feeds cannot replicate, grounded in their own analysis and their own access.

That intelligence powers the feeds they deliver to their own customers, including machine-readable rules across multiple formats and indicators distributed through standard protocols like STIX and TAXII, integrated machine-to-machine into customer environments. The analysis depth also sharpens their incident response work, turning samples observed in live engagements into structured, reusable intelligence.

Just as importantly, they achieved all of this without trading away control. Running on-premises, the team keeps their most sensitive data and their most valuable intelligence entirely their own, while still operating with full analytical capability and the evidence to stand behind everything they publish.

For a provider whose reputation rests on the quality of the intelligence it produces, that combination, depth, transparency, and sovereignty, is the foundation everything else is built on.

“Our intelligence is our most valuable asset, so it has to stay ours. Running VMRay on-premises gives us full control of our data with no loss of capability, and we always understand why a sample was flagged.”

 

Head of Cyber Threat Intelligence

Table of Contents

Explore valuable Cybersecurity Resources

Cybersecurity Blog

Check our latest insights on malware, phishing, sandboxing, AI in cybersecurity, and much more.

VMRay Academy

Browse the courses about alert handling, deep threat analysis and response, threat intelligence generation and more.

Malware Analysis Reports

See real-world examples of VMRay’s best-in-class malware analysis and detection platform.