Detection engineering
Check whether EDR, SIEM, Sigma-derived, Snort, or Suricata detections fire—and whether the resulting records are useful for investigation.
Controlled C2 interaction · Private preview
Proofmetry recreates the server-side C2 interaction a supported malware variant expects. Choose a predefined behavior test, run the customer-held sample in your lab, and use your existing tools to capture the resulting host and network activity.
Proofmetry platform
Customer environment
The Proofmetry platform
Proofmetry provides the server-side interaction for the selected behavior test. The customer-held sample performs the behavior, and your tools capture the endpoint and network effects.
Your tools remain the system of record. Proofmetry does not include a telemetry recorder; your team controls telemetry, labels, and evaluation results.
How it works
Start with the behavior your team needs to see, then confirm that the customer-held sample matches current coverage.
Name the detection gap, data requirement, or coverage question.
Match the customer-held sample to a supported family and variant.
Confirm authorization, containment, egress controls, and collection tools.
Proofmetry provides the controlled interaction; the customer-held sample performs the selected behavior.
Compare customer-collected records with alerts, rules, labels, and expected behavior.
C2Looper
Static analysis mapped eight command handlers in one DLL variant; seven handler paths were observed during isolated execution. Directory enumeration remained static-only. Analyst-operated research tools captured discovery, file, process, memory, and network activity from the analyzed sample without contacting GitHub or attacker-controlled infrastructure.
Why this exists
Static analysis can reveal a capability, while attack simulation approximates behavior with a substitute. Proofmetry takes a different path: it lets the supported malware sample perform its own post-C2 behavior so your sensors can observe the native implementation.
It may be dormant, seized, inaccessible, or unsafe to contact while the sample continues to poll.
The endpoint and network activity needed for rule testing remains behind a missing command path.
New sensors, parsers, rules, and model versions create new questions about what the lab will capture.
Rules and datasets
Your tools collect the telemetry. Proofmetry identifies the supported variant, selected behavior test, and expected observations so your team can interpret and label each run.
Check whether EDR, SIEM, Sigma-derived, Snort, or Suricata detections fire—and whether the resulting records are useful for investigation.
Use the sample identity, selected test, time window, and observed outcome to label telemetry from your own tools for feature development, holdout testing, and model regression.
Scope matters. The data describes one sample, one environment, and its sensors. It is not a balanced corpus, and Proofmetry does not claim that it represents every infection or improves model performance.
Security & trust
Proofmetry is not a public execution service and this site does not accept sample uploads. Supported tests do not require live attacker infrastructure. Customers retain control of authorization, sample handling, isolation, egress, execution, and telemetry.
Review security & trustPrivate preview
Share your work contact details. In the follow-up, we’ll discuss the malware family or sample hash, behavior test, and evidence your tools need to capture.
Get a demo U.S.-based organizations · Business email required