Home Solutions Intezer
Endpoint · SOC Automation · Genetic Code Analysis
Intezer logo

Code DNA analysis
puts SOC L1 work on autopilot.

Intezer breaks every executable file into thousands of code “genes”. It compares them with a database of 40B+ fragments from known software, both legitimate and malicious. The platform automatically tells you whether a file is malware, trusted or suspicious, names its family and shows any links to APT groups.

How Genetic Analysis works

Every program is
built from reused code.

Malware authors reuse loaders, crypters and syscall stubs from public toolkits instead of writing everything from scratch. Intezer finds these fragments.

01
Disassembly
Any PE, ELF, Mach-O, .NET, Java or script. Intezer breaks the binary into functions, and the functions into blocks.
02
Extracting “genes”
Each block becomes a “gene”, a normalized code fragment. An average sample has 200-2,000 genes.
03
Comparison with the database
40B+ genes from thousands of known malware families and legitimate vendors. The search takes 1-10 seconds.
04
Verdict + attribution
The family, code fragments, links to APT campaigns, a ready YARA rule, the execution flow and IOCs.
Signature / IOC
“Is it the same hash?”

Change the compile time or a single byte, and the signature no longer matches. Malware authors rebuild their samples daily.

  • Breaks after recompilation or repacking
  • Needs the exact original sample
  • Can’t tell the family or the author
Genetic Analysis
“Is it the same code?”

It compares the semantics of blocks, not hashes. Recompilation doesn’t throw it off: 90% of genes stay the same.

  • Attribution to a specific family and author
  • Works even with packers and obfuscation
  • Generates YARA rules automatically
Autonomous SOC

Make every L1 analyst 10× faster.

Intezer Autonomous SOC automatically pulls samples from your EDR/SIEM/email alerts, runs them through Genetic Analysis, issues a verdict and closes or escalates the case.

  • Triage of 100% of alerts - 24/7, with no vacations or sick days.
  • Average time per alert ↓ from 30 minutes to 12 seconds.
  • 95% true-positive precision according to Intezer customer statistics.
  • Ready-made playbooks for CrowdStrike, SentinelOne and Defender.
Live alert triage
last 1 min
12:04:11
CrowdStrike alert · suspicious.exe · WS-FIN-014
Auto-analysis · 2.1s
Trusted
12:04:08
Defender alert · invoice.dll · DESKTOP-1142
Family: BumbleBee loader · isolate host
Malicious
12:04:02
SentinelOne alert · update_8.7.bin · SRV-DEV-04
Genetic match: Notepad++ · false positive
Trusted
12:03:56
Splunk alert · unusual PowerShell · WS-MKT-007
Memory scan triggered, awaiting result
Suspicious
12:03:43
Email Security · attachment.iso · finance@
Family: QakBot loader · block + sandbox URL
Malicious
487
alerts / day
98%
auto-resolved
12s
avg. time
9
L2 escalations
Integrations

Connects to your existing stack in an hour.

Intezer doesn’t require replacing your EDR or SIEM. It connects through ready-made connectors and works on top of your telemetry.

Endpoint Detection & Response
SIEM & SOAR
Email · Ticketing · Chat
+ An open REST API and Python SDK for your own integrations. Ready-made connectors for Microsoft Azure Logic Apps.
Use cases

Where Intezer pays off in the very first week.

Alert triage 24/7

Any EDR/SIEM/email alert with an attached file is automatically analyzed and closed or escalated in seconds.

Memory forensics

Intezer Endpoint Scanner dumps memory and finds fileless implants, hollowing and process injection.

Threat hunting by family

“Find all hosts where code similar to BumbleBee has been seen”: Intezer searches by genes across the whole environment.

Auto-YARA generation

Based on the unique genes it finds, Intezer creates a YARA rule ready to be published to the SIEM or EDR.

Phishing email forensics

Analysis of attachments and payloads. Intezer finds the campaign and links it to an APT group through the loader family.

Supply chain scanning

Checking new vendor software before purchase: what components it contains and whether it matches known loaders.

CYBER BOOST × Intezer

CYBER BOOST supplies and supports Intezer in the region.

We supply licenses, help connect Intezer to your existing EDR/SIEM stack, write triage playbooks and train L1 and L2 analysts.

3 days
typical PoC: connecting to the EDR, triaging 100 alerts and reviewing the results.
90 %
of L1 alerts are closed automatically for customers.
RU/EN
playbooks and analyst training in two languages.
Cloud / On-prem
we support both deployment options and air-gapped installations.
FAQ

Frequently asked questions about Intezer.

What is Genetic Malware Analysis?
Genetic Malware Analysis is Intezer’s own technology. It disassembles executable code and breaks it into “genes” (small reusable code fragments). Then it compares them with a database of 40B+ genes from known software, both legitimate and malicious. This links a new file to a specific malware family or a trusted vendor without signatures.
Does Intezer replace our EDR?
No. Intezer works on top of EDR (CrowdStrike, SentinelOne, Microsoft Defender, Sophos and others), SIEM and email security. The platform checks every alert automatically and marks it as malware, clean or suspicious. This saves L1 analysts 60-90% of their time.
Can Intezer be used for memory forensics?
Yes. Intezer Endpoint Scanner dumps the memory of running processes and runs genetic analysis on it. It finds fileless implants, packers, injections and hollowing that can’t be seen on disk.
Which integrations are available out of the box?
CrowdStrike Falcon, SentinelOne, Microsoft Defender, Sophos Intercept X, Splunk, Microsoft Sentinel, Splunk SOAR, Cortex XSOAR, Tines, Slack, Microsoft Teams, ServiceNow and JIRA. There is also a REST API and a Python SDK for your own integrations.
How does Intezer handle private data?
By default the platform runs in the cloud, but you can submit samples in private mode, so they are not shared with the community. For regulated industries there is an on-prem or air-gapped option. We can discuss how it fits your environment.
Which file formats are supported?
Windows PE/PE32+, .NET assemblies, Linux ELF, macOS Mach-O, Android APK, scripts (PowerShell, JS, VBA, Python), office documents with macros and ISO/IMG containers. Analysis is both static and dynamic (sandbox).
Request · Intezer

A PoC in 3 days. No integration with production telemetry.

We’ll take 100 of your samples and alerts and run them through Intezer. Our report shows how many are closed automatically, how many are escalated and how the average time per alert changes.