July 23, 2019
This screenshot showsYou can't really throw tens of years development into the trash and start from scratch every time.It is practically impossible to reuse binary code, so they would need to hack into the North Korean government, steal their source code, and then recompile it with their modifications.For example, if you know that you're dealing with an APT or an advanced threat actor, then the response itself would be significantly different than if you were dealing with just a common internet scam.So, you see that even years after an attack, the original malicious code is still being used to create new malware.Just like Google must index more and more websites every day, we need to index more software and more malware every day, so our database is constantly growing.

Therefore, focusing on and accelerating the response is a very significant value you get from understanding the origins of code in the file.For example, if you have a file from Microsoft which another solution or security system might deem suspicious because of its behavior, Intezer will recognize it as legitimate because 90% of its code has been seen in other Microsoft products.So, this scenario is very, very unlikely.help you understand what you are dealing with.This screenshot showsThat tells us right away that this cannot be a Windows file.

Right after I uploaded the file and analyzed its DNA, you can see we have extracted 462 genes or tiny pieces of code.So, we reduce a lot of the false positives from other security systems because we just identified the DNA as that of a trusted vendor.Can you show us an example of Intezer Analyze™'s DNA mapping in action? Here is a case of a suspicious file, claiming to be a Windows file.So, while Skype looks like it behaves bad, we know it is good as the code originated from and belongs to Microsoft.This screenshot showsSo, software really is evolutionary in both legitimate and malicious cases.

