Close More Cases. In Less Time.

ThreatDetective is the force multiplier for your malware analysis team. SONAR, our Human-in-the-Loop AI, allows analysts to collaborate and close the gap between detection and analysis faster than ever before. No more mazes of fractured tooling: we provide one coherent interface with everything you need.

SONAR · invoice_Q3_final.pdf.exe
MaliciousHigh confidence
3ATT&CK
9YARA hits
1Processes
617Connections
37 behaviors · persistence via Run key · browser credential theft · exfil over SMTP
0 m · Surface · harbor patrol

Fast and Accurate

Clear reporting: hashes, technique mapping, and a verdict you can defend. Customize what your team sees, and send the right details to the right audience. 100% Signal. Zero Noise.

Drop output straight into your SIEM, SOAR, or threat intelligence platform.

PulseFile #676 — chained_unpack-1783741429 ×
◯ Samplechained_unpack.exe81ff
→
⊞ Unpacked177-676-unpacked-de84…de84
hexdisasm
Contains_ascii_charsMatch on file i sampleprogram_lookerDetect_Program_Cannotnew_rulerest_testingest_test
Functions 2Imports 3Code ExplorerSave to Investigation
Code Explorer from entry | callees | depth 2
RootInternalExternalThunk
Call graph: entry calls FUN_1400010a0, which calls ExitProcess, VirtualAlloc and VirtualProtect
entry @ 0x140001000 (24 instructions)
AddressBytesMnem1400010004883ec38SUB14000100441b911000000MOV14000100a4c8d05ef2f0000LEA140001011ba00200000MOV140001016c74424280b0000MOV14000101e488d0ddb0f0000LEA140001025c74424200a0000MOV14000102de86e000000CALL14000103241b911000000MOV
200 m · Twilight · echolocation

Watch malware run on a machine
it believes is real.

Analytic tools sit outside the guest, giving malware nothing to detect. Easily patch evasive behaviors to track the full execution chain, including the paths malware tries to hide. Every process, file, key and packet it touches is recorded.

PulseFile #676 — chained_unpack-1783741429Dynamic ScanScan Results ×
Dynamic ScanSave to Investigation
cross_process_writeunpack_rw_to_rx FIREDprocess_hollowingremote_thread_injectionsection_injectionreflective_loadapc_injection
air_gappedVM
completedStatus
100.1sDuration
247Hook entries
6Memory dumps
7Entry types
Detection entries
process_open: 167process_create: 3memory_protect: 50memory_alloc: 14section_map: 7section_create: 3detection_dump: 3
Raw entriesScan logs
ProcessesRaw firehose
▾pid 60046
chained_unpack.exe77
pid 143650
pid 261239
pid 81220
▸pid 276815
pid 57613
pid 428011
pid 6806
pid 14683
chained_unpack.exe pid 5276 · 77 events
C:\Users\Public\chained_unpack.exe
◂ opened by pid 2612 ×8◂ opened by pid 6004 ×5◂ opened by pid 516 ×1+ Add to investigation
◷ Timeline▪ By category
MEMORY16:36:13.922 memory_protect base_address=140707892118800 region_size=8 new_protect=PAGE_READWRITE …+MEMORY16:36:13.922 memory_protect base_address=140707892117504 region_size=4096 new_protect=PAGE_WRITECO…+MEMORY16:36:13.922 memory_alloc base_address=43450871808 region_size=12288 alloc_type=MEM_COMMIT alloc_t…+MEMORY16:36:13.923 memory_protect base_address=140707892105216 region_size=13600 new_protect=PAGE_READON…+MEMORY16:36:13.923 memory_alloc base_address=43450867712 region_size=12288 alloc_type=MEM_COMMIT alloc_t…+MEMORY16:36:13.923 memory_alloc base_address=0 region_size=2949120 alloc_type=MEM_RESERVE alloc_type_raw…+
4,000 m · Abyss · deep analysis

Unpack it to
the last byte.

SONAR, our Human-in-the-Loop AI, allows you to use plain English prompts to control the VM, dump a region, draft YARA rules, decompile, and tear apart sophisticated Advanced Persistent Threats (APTs). Modify or rewrite every line of code for speed with complete transparency, never a black box. Multi-layer unpacking and targeted memory dumps.

The report a reverse engineer would write, without waiting a week. Every finding defensible and Board-ready.

Would you like to continue this investigation?
›
Run a dynamic scanExecute a sample and capture behavioral hooks
›
Query live memoryPause at a detection and inspect live memory
›
Scan with YARA rulesRun YARA rules against sample or memory dumps
›
Decompile the sampleOpen the binary for static code analysis
›
Start a triage workflowAutomated investigation across all artifacts
write a yara rule to detect Unpack RW to RX minimize false positives
Executing: Running: Present a YARA rule to the user for review and editing.
YARA rule: Generated YARA rule: Detect_Unpack_By_Section_Name
This approach targets specific, known packer artifacts within the file. Please review the rule. We can run it, save it, or I can try another approach if this one isn't to your liking.
Ask the assistant…
➤ Send
AgenticAuto-executeDebug
413.3k tokens · 9 tools · 107.6s · air_gapped⚡ Dynamic Scan
Unpack · invoice_Q3_final.pdf.exe → payload.binAgentTesla · 188 KB
LAYER 1 · CUSTOM XOR · 214 KBLAYER 2 · RC4 · 203 KBLAYER 3 · 196 KBpayload.binAGENTTESLA · 188 KBMEMORY · 0x00400000 · 3 REGIONS · CONFIG AT 0x0041C2A0CONFIG
↑ 0 m · Surface · your turn

Dive deeper.

Bring your own samples. See ThreatDetective analyze them live, with your team, on a 30-minute call.

© 2026 ThreatDetectiveFollow on LinkedInAbout

ThreatDetective (also written Threat Detective) is an AI malware analysis platform for security teams: fast triage, sandbox detonation, unpacking and defensible reports in one interface.