PRIMARY RESEARCH
isolation-first labIsolation-First Malware Analysis
An isolation-first malware-analysis lab for controlled acquisition, static triage, evidence handling, behavior hypotheses, and reproducible rollback before any separately authorized dynamic execution.
Verified foundation
- A layered virtual-lab architecture separates the host, chamber controller, acquisition and static-analysis guest, and separately authorized dynamic-analysis target.
- The operating procedure defines sample identity, custody, network isolation, static-analysis stages, stop conditions, and verified cleanup.
- Raw samples and payload-bearing evidence remain inside the isolated lab boundary rather than entering synced notes, Git, cloud storage, or the public site.
Research focus
01
Controlled acquisition and cryptographic identity
02
Static triage and reverse-engineering discipline
03
Evidence separation and confidence labeling
04
Rollback and containment verification
Evidence boundary
- Real-sample work remains gated by live isolation, snapshot, tooling, and incident-response prerequisites.
- Investigation results appear here only when supported by sanitized public evidence.