Malware Lab
Our Malware Lab analyses new threats on a daily basis through the threat hunting network, with the aim of understanding the technological evolution of cyber attacks – in particular in relation to infection vectors, evasion techniques, persistence and dissemination – in real time. These activities allow us to consolidate strategic knowledge to continuously improve the effectiveness and timeliness of incident response and actively contribute to the dissemination of information on emerging threats within the expert community, as well as among customers, partners and institutions.
Malware Lab analysts are constantly researching and testing innovative tools and methodologies for advanced malware analysis, with the goal of increasing accuracy and coverage against emerging techniques used by attackers. The team also developed an automated process for the daily extraction of Indicators of Compromise (IOCs) from dozens of malware samples, feeding our proprietary Knowledge Base. It is actively involved in the development of tools dedicated to malware analysis and designed to support incident management and response.
Threat analysis
The Malware Lab is a Research Centre specialising in the study of the main techniques adopted by malware, with a focus on evasion, dissemination, persistence and infection.
We continuously analyse the most relevant malware campaigns, identifying the way they work, the technologies used and profiling the leading threat actors active on the international scene.
To support these activities, the Malware Lab makes use of a dedicated honeynet, designed to analyse new malware campaigns targeting the national perimeter in real time.
Activities
- Malware analyses
- Support to incident management
- Threat Intelligence
- Threat Hunting
- Posture assessment and improvement
- Development of native tools for analysing or removing malware
- Reporting on active malware campaigns
- Reporting on current malware techniques
Tools
- Static and dynamic analysis technologies
- Natively developed tools
- Threat hunting tools
- Threat intelligence tools
- Honeynet
Corrado Aaron Visaggio
Group Chief Scientist Officer & Malware Lab Director
Corrado Aaron Visaggio is professor of Computer Security at the Department of Engineering at University of Sannio. He authored more than one hundred papers on International Conference proceedings and journals of Security Information. He leads the malware lab and the Research Department at Defence Tech and the security lab at University of Sannio. His main fields of research are: malware analysis, artificial intelligence applied to malware detection, and threat intelligence. He serves in Editorial Boards of several Infosec Journals and in the Program Committee of different International Conferences. He is in the Management Board of the CINI-National Cybersecurity Lab.