Book a demo call with us
Cross icon
Malware
Threat-intel

Hybrid Analysis

A free public malware analysis sandbox (powered by CrowdStrike Falcon Sandbox) that executes suspicious files in isolated environments and provides detailed behavioral reports, YARA matches, and IOC extraction.

Hybrid Analysis

What is Hybrid Analysis?

Hybrid Analysis is a free public malware analysis platform powered by CrowdStrike's Falcon Sandbox technology. It executes suspicious files in isolated virtual environments across multiple operating system configurations and records everything that happens: process creation, file system modifications, registry changes, network connections, and API calls. The resulting behavioral report gives analysts a detailed view of what a piece of malware actually does when it runs, going far beyond what static analysis or signature scanning can reveal. The platform also extracts indicators of compromise including domains, IP addresses, and file hashes, and matches samples against YARA rules. Because it is publicly accessible and free, it is widely used for rapid triage of suspicious files received via email, downloaded from the web, or found on compromised endpoints.

How does Hybrid Analysis work with Qevlar?

Qevlar can submit suspicious files or hashes to Hybrid Analysis as part of an automated investigation workflow. When an alert involves an unknown executable or a file with suspicious characteristics, Qevlar uses Hybrid Analysis to obtain a behavioral verdict and extract IOCs that can be used to search for related activity elsewhere in the environment.

Want to help your analysts focus on the most critical alerts?

Frequently asked questions

What is Hybrid Analysis?

bar
bar

Hybrid Analysis is a free public malware analysis sandbox powered by CrowdStrike's Falcon Sandbox. It executes suspicious files in isolated environments and returns detailed behavioral reports, YARA matches and extracted indicators of compromise.

What can you do with Hybrid Analysis in Qevlar?

bar
bar

Qevlar can submit suspicious files or hashes to Hybrid Analysis as part of an automated investigation, obtaining a behavioral verdict and extracting IOCs to search for related activity elsewhere in the environment.

Do analysts need to run files through the sandbox themselves?

bar
bar

No. Qevlar handles submission and result retrieval automatically when an alert involves an unknown executable, so the behavioral verdict is ready without manual effort.

Can Qevlar pivot on Hybrid Analysis results?

bar
bar

Yes. The IOCs extracted from a detonation can be pivoted across your connected SIEM, EDR and email sources to find anything related across the estate.

Other integrations