Malware and phishing analysis for government and military, deployed on your terms.

The most targeted threats, under the tightest constraints on how you operate. Accurate verdicts your automation can act on, behavioral depth when you need it, and a deployment model that meets your obligations.

100+ Government organizations worldwide trust VMRay to

Create their own threat intelligence

Empower reliable security automation

Accelerate incident response

01 / CONTEXT

What makes public sector defense different

Three conditions change what an analysis layer has to do.

SCALE

Alert volume beyond what manual review can absorb

CONSEQUENCE

A missed detection carries consequences beyond the organization

REGULATION

Regulation decides where analysis may run

02 / CAPABILITIES

What VMRay provides public sector teams

Accurate enough to automate on, deep enough to build intelligence from, available where your obligations require.

01 / AUTOMATION

Verdicts your automation can act on

Automation is only as reliable as the analysis feeding it. False positives put a human back in every loop.

  • Definitive verdicts: malicious, suspicious, or benign
  • Scored IOCs structured for automated use
  • Native integrations and REST API into EDR, SIEM, SOAR, and TIP
  • Recursive analysis of the full delivery chain, not only the submitted file
02 / THREAT INTELLIGENCE

Intelligence built on the threats aimed at you

Public sector organizations are targeted specifically. Intelligence should reflect the threats actually arriving, not the landscape in general.

  • Malware configuration extraction: C2 servers, encryption keys, campaign identifiers
  • MITRE ATT&CK TTP mapping
  • STIX 2.1-ready output for sharing and correlation
  • YARA rules generated from observed behavior
03 / DEPLOYMENT

Four deployment models, one analysis capability

Where VMRay runs is your decision, and it does not cost you capability. Feature parity is maintained across deployment models wherever technically applicable.

  • VMRay Cloud: instant to deploy, always current
  • European Sovereign Cloud: hosted in Germany, EU law
  • On-premises: full control of your infrastructure
  • Air-gapped: maximum isolation, no connection required
Same analysis. Same accuracy. Wherever you run it.
Deployment options feature brief
FIG 1 / SIGNAL · CONTEXT · DEPLOYMENT VERDICT BEHAVIORAL DETAIL ON-PREMISES AIR-GAPPED CLOUD EUROPEAN SOVEREIGN CLOUD
03 / THE FLOW

How analysis fits into the flow

Samples arrive from across the stack. Verdicts and indicators return to every system that needs them.

INPUTS Files & executables Emails & URLs Alerts EDR / SOAR VMRay Platform Accuracy & clarity SOC EDR ALERT ENRICHMENT MALWARE TRIAGE SOAR ALERT INVESTIGATION PHISHING TRIAGE USER-REPORTED PHISHING CTI THREAT INTELLIGENCE GENERATION THREAT HUNTING CERT INCIDENT RESPONSE MALWARE ANALYSIS
04 / CUSTOMER STORIES

How public sector teams are using VMRay

Three organizations, three starting points. Automation at scale, threat intelligence development, and analysis depth for a lean team.

FEATURED CUSTOMER STORY

Building in-house threat intelligence at an intra-governmental organization

The team wanted independence from generic external feeds, and intelligence specific to the actors targeting them. Behavioral analysis gave them indicators they could verify, configurations they could attribute, and findings in a vocabulary their peer CERTs already shared.

Read the full story
  • High-confidence indicators extracted from observed behavior
  • Malware configuration extraction revealing C2 infrastructure
  • ATT&CK-mapped findings shared with peer CERTs

VMRay’s analysis, known for its reliability and precision, has become the cornerstone of our robust security posture, enabling us to build actionable threat intelligence against the specific threats we face.

Head of Computer Security & Incident Response Capability
European Intra-Governmental Organization
CUSTOMER STORY

Scaling automated defense across a 100,000-staff government department

An automation pipeline spanning EDR, SOAR, and TIP, fed by an analysis engine that took manual review back out of the loop.

Read the full story
CUSTOMER STORY

Raising analysis depth at a major North American city administration

Depth and clarity of output for a small team, without adding review overhead.

Download full story
05 / IN THE PRODUCT

What this looks like in the product

One analysis, six views. Move through the tabs to follow a single sample from verdict to extracted configuration.

Click any tab to move through the analysis
VMRay Platform Verdict
MALICIOUS
Classifications
Injector Downloader
Threat names
Mal/HTMLGen-A Mal/Generic-S Pikabot
Dynamic Analysis Report
Xjgkkltfdhdfhfjg.exe
Created last month
Windows Exe (x86-32)
Remarks (1 / 1)
Anti-Sleep Triggered (0x0200000E) โ€” the overall sleep time of all monitored processes was truncated from 43 s to 10 s to reveal dormant functionality.
VMRay Threat Identifiers 19 rules ยท 72 matches
ScoreCategoryOperationCount
5 / 5 Extracted Configuration Pikabot configuration was extracted 1
A configuration for Pikabot was extracted from artifacts of the dynamic analysis.
VMRay Platform Threat Identifiers
VMRay Threat Identifiers 19 rules ยท 72 matches Behaviour scored
ScoreCategoryOperationCount
1 / 5Discovery Enumerates running processes1
5 / 5Extracted Configuration Pikabot configuration was extracted1
A configuration for Pikabot was extracted from artifacts of the dynamic analysisC2 recovered T1027 ยท Obfuscated Files or Information
2 / 5Persistence Hides a known RMM tool1
1 / 5Defense Evasion Masquerades process name2
1 / 5Collection Reads clipboard contents1
0 / 5Execution Spawns child process3
VMRay Platform MITRE ATT&CK Matrix
MITRE ATT&CK MatrixWindows
Techniques observed during dynamic analysis, mapped to tactics.
Initial
Access
Execution
Persistence
Privilege
Escalation
Defense
Evasion
Credential
Access
Discovery
Lateral
Movement
Windows Management Instrumentation
Scheduled Task
Scheduled Task
Registry Run Keys / Startup Folder
Scheduled Task
Modify Registry
Disabling Security Tools
Hidden Window
Credentials in Files
System Information Discovery
Security Software Discovery
File and Directory Discovery
Remote File Copy
High severity Medium Low 13 techniques ยท 8 tactics
VMRay Platform Network Analysis
General
168.55 KBsent,18.16 MBreceived
6ports23817, 23759, 80, 53, 443
25contacted IP addresses
11files downloaded
1malicious host detected
DNS
22queries for22domains
7queries returned errors
HTTP / S
19URLs,13contacted servers
26sessions detected
Contacted infrastructure (25 IP addresses)
DEGermany9
USUnited States6
FIFinland3
CZCzechia2
HUHungary2
NLNetherlands2
SGSingapore1
31 Hosts
RequestsSeverity
185.215.113.44
๐Ÿ‡ฉ๐Ÿ‡ช:23759
65.108.69.168
๐Ÿ‡ซ๐Ÿ‡ฎ:16278
185.215.113.35
๐Ÿ‡ฉ๐Ÿ‡ช:80
msdl.microsoft.com
๐Ÿ‡บ๐Ÿ‡ธ:443
server5.trumops.com
๐Ÿ‡บ๐Ÿ‡ธ:443
212.192.241.62
๐Ÿ‡จ๐Ÿ‡ฟ:80
iplogger.org
๐Ÿ‡บ๐Ÿ‡ธ:443
91.219.236.207
๐Ÿ‡ญ๐Ÿ‡บ:80
TCP Sessions (11)
TLSSrc IPSrc PortDest IPDest Port
โœ•192.168.0.3349865185.215.113.4423759
โœ•192.168.0.3349452185.215.113.4423759
โœ•192.168.0.3349360185.215.113.4423759
โœ•192.168.0.3349758185.215.113.4423759
โœ•192.168.0.3349551185.215.113.4423759
โœ•192.168.0.3349649185.215.113.4423759
VMRay Platform Artifacts & IOCs
Filter 93 other artifacts
ALL TYPES70
FILE1
URL64
IP2
PROCESS3
Verdict
TypeValue
FileC:\Users\RDHJ0C~1\Desktop\5Dq6sWcmD.dll.ocx+2
IP104.168.155.143
IP167.172.248.70
URLhttps://197.242.150.244:8080
URLhttps://159.89.202.34
URLhttps://206.189.28.199:8080
URLhttps://45.235.8.30:8080
URLhttps://201.94.166.162
URLhttps://188.44.20.25
URLhttps://183.111.227.137:8080
Details
Related VTIs (1)
URLhttps://197.242.150.244:8080
Original URLshttps://197.242.150.244:8080
CategoriesExtracted
IP Addresses197.242.150.244
User-Agentsโ€”
VMRay Platform Malware Configuration
5 / 5Malware Configuration
A configuration for Pikabot was extracted from artifacts of the dynamic analysis.
Sample file
File name
5Dq6sWcmD.dll.ocx
File size
548.00 KB
MIME type
application/vnd.microsoft.
portable-executable
MD5
b232b0df5d369ef0f7597f215c32043a
SHA1
4a4b865f1243ea1983044337500448e38557af0
SHA256
19fcf233637e0ca65c4eef3b234d3c79ad
1604b524da1b1f292cf7e7dcaf13aa
ImpHash
089cd79cc1eaac3fa7d34f758db58a4a
Extracted C2 commands recovered from memory
std::string::assign(&v45, "shi", 3ui64);
*(_QWORD *)sub_1800149DC((__int64 *)v61, (__int64)&v45) = func_shi;
// โ€ฆ
std::string::assign(&v45, "dij", 3ui64);
*(_QWORD *)sub_180014ADC((__int64 *)v61, (__int64)&v45) = func_dij;
// โ€ฆ
std::string::assign(&v45, "dex", 3ui64);
*(_QWORD *)sub_180014BDC((__int64 *)v61, (__int64)&v45) = func_dex;
// โ€ฆ
std::string::assign(&v45, "sdl", 3ui64);
*(_QWORD *)sub_180014CDC((__int64 *)v61, (__int64)&v45) = func_sdl;
Extracted configuration Pikabot configuration was extracted Go to memory dump
06 / INTEGRATIONS

Integrations with your existing security stack

VMRay connects into the tools your team already runs. Verdicts and indicators move into EDR, SIEM, SOAR, and threat intelligence platforms through native connectors or the REST API, without manual handoff between consoles.

VMRay's ability to generate reliable IOCs, extract malware configurations and map the output on the MITRE ATT&CK framework support seamless collaboration and threat intelligence sharing among government CERTs.

Security Analyst
GovCERT in Europe
FIG 3 / INTEGRATION ARCHITECTURE VMRay integration architecture across EDR, SIEM, SOAR, and threat intelligence platforms
07 / RESOURCES

Additional resources

WEBINAR WITH FORRESTER

Advanced malware detection in government

Watch the panel
WEBINAR

Advanced government threat models with malware insights

Watch the webinar
BLOG

VMRay blog

Read the blog
GET STARTED

See VMRay on a threat from your environment

Submit a sample and see the verdict, the behavior, and the indicators returned.