It’s day #2 for me at VMRay but in many ways I’ve really just come ‘home’ having already worked with the founders of VMRay for quite a few years when I ran Sunbelt Software’s Advanced Technology Group (sold to GFI and now spun out as ThreatTrack).
When I got the offer to come to VMRay I leapt at it. Knowing what Carsten and Ralf and the rest of the team had done already with CWSandbox I was certain that they would be on to something good this time around.
When we first commercialized dynamic malware analysis systems, simple user-mode hooking was sufficient. We had to quickly migrate to kernel-mode hooking to mitigate user-mode detections by malware. Then malware started adding VM detection and obfuscation to bypass or otherwise fool analysis tools like sandboxes.
One problem – VM detection – somewhat solved itself as virtualization in production environments became ubiquitous. But that simply opened the door to the constant whack-a-mole challenge of making the analysis environment detection-proof.
VMRay has addressed that by moving the monitoring to the hypervisor. By virtualizing the hardware and running on bare metal VMRay’s analyzer is undetectable by malware and also delivers substantially better performance than alternatives.
Faster … undetectable .. that’s a pretty unbeatable combo for a security vendor. I’m responsible for sales at VMRay and truth be told I have a lazy streak – I have a strong preference for products that have such obvious benefits and competitive advantages they sell themselves. Such is the case with VMRay.
If you’re still not convinced, check some sample reports or watch the video of VMRay analyzing the Wiper malware used in the Sony hack.
Auf Wiedersehen,
Chad Loeven
VP Sales and Marketing