GLIMPS Malware Expert is a file and malware analysis platform designed for cybersecurity professionals, including Security Operations Center (SOC) and CSIRT teams. It functions as a centralized console for analyzing files and URLs, utilizing a proprietary Deep Learning engine for technical information extraction and a dynamic analysis engine for behavioral observation. The platform executes files within a Windows sandbox to collect system logs and behavioral data, and it processes archives and sub-files to extract technical details such as Indicators of Compromise (IoCs), observables, and character strings. Detection capabilities are supported by AI-based threat categorization, a proprietary blacklist of SHA256 signatures, and integration with the NSRL database.
The system contextualizes analysis results by correlating findings with external threat intelligence sources and mapping data to the MITRE ATT&CK framework. It provides detailed analysis reports, a dashboard for tracking key performance indicators (KPIs), and an alerting system for incident response teams. The interface offers secure document visualization and presents information at multiple levels to accommodate different security roles. Based on analysis findings, administrators can generate rules for other cybersecurity solutions. Platform access is secured via TOTP two-factor authentication.