GORILLE analyses files and recognises the malware inside them through morphological analysis: it compares the structure of the code, not its fingerprint. No signature, no hash — which is why it recognises variants no one has seen yet. What that capability changes for you depends on where you place it: when an alert comes in, in the middle of an incident, across the files on your estate, inside your software chain, or on an analyst’s workstation. Six situations, six answers.
WHERE DO YOU START?
Common scope across the three products: all file types — executables, documents and scripts — on Windows, Linux, Android and macOS. Static and dynamic analysis. French technology, developed in France since 2017.
01 · ALERT TRIAGE
Your EDR flagged a file. Is the alert real?
For the SOC analyst — “I have to decide before my shift ends, without missing the serious one.”
The EDR observes a behaviour, but it cannot always name the binary that produced it. You hand it the file: GORILLE Server returns its verdict in under a second — malicious or not, which family, and at what correlation rate with samples already known. The alert stops being a question mark and becomes a documented decision.
- Verdict and family attribution in under a second, through morphological analysis of the code — no signature, no hash
- Recognises 0-day variants and polymorphic strains that signature engines let through
- Identifies the packer, unpacks the file and analyses the code that actually runs
- Called through the REST API from your EDR, XDR, SIEM or SOAR: direct IOC enrichment, not one more interface
02 · INCIDENT RESPONSE
You need to characterise the threat while the incident is running.
For the head of SOC and the CERT — “My analysts are saturated and management is waiting for an answer.”
In a crisis, time goes into manual characterisation, sample by sample. GORILLE takes that share of the work: it names the malware, ties it to a known family, measures which portions of code it shares with other samples, and produces the MITRE ATT&CK & DEFEND matrix of the techniques it carries. Your analysts keep their time for remediation.
- Family attribution and a quantified correlation rate with known samples
- MITRE ATT&CK & DEFEND matrix and PDF report, usable as is in a crisis cell
- Binary comparison: which portions of code are shared, and in what proportion
- CTI enrichment: the sample is tied to campaigns already documented
- GORILLE Expert takes over when you need to disassemble and go down into the code
03 · HUNTING FOR DORMANT THREATS
Is malware already sleeping in your files?
For the CISO — “What is my real exposure, beyond what the EDR reports?”
A binary dropped on a workstation can wait weeks before it runs. As long as it does nothing, it produces no behaviour: behavioural detection cannot see it. GORILLE Patrol analyses files at rest, in campaigns, and identifies those carrying malicious code — before detonation, not after.
- Schedulable campaigns across all or part of the estate, static and dynamic
- Detection on the file at rest, before any execution — so before the behaviour exists
- Every malware found is named and tied to its family, not merely flagged
- On-premises analysis: the files on your estate never leave your infrastructure
- Strengthens the EDR in place instead of replacing it
04 · SUPPLY CHAIN PROTECTION
You need to check deliverables and dependencies before integration.
For the CISO, the CIO and the software vendor — “I control neither the code that comes in, nor what my customers receive from me.”
A supplier’s deliverable, a third-party dependency, the binary coming out of your build chain: every file crossing your organisation is a way in. A digital signature attests to a sender, not to the harmlessness of a payload. GORILLE Server is called through the REST API at whichever point of the flow you want to control, and returns its verdict on each file before it goes through.
- Detects malicious code injected into a deliverable, signed ones included
- Checks files of external origin before integration: dependencies, SDKs, supplier deliverables
- Fits into the continuous integration chain through an API call, as a blocking gate or in audit mode
- Verifies that your backups carry no malware — a restore must not reinstall the threat
- Sovereign control of the chain: on-premises, none of your deliverables leaves your walls
05 · REVERSE ENGINEERING
You have to disassemble this binary and read its code.
For the reverse engineer and the malware analyst — “Is it precise enough, and does it actually save me time?”
GORILLE Expert disassembles executables, extracts the structure of the code and compares it against millions of samples. Morphological analysis works on the shape of the code itself: it withstands packing, obfuscation and polymorphism. The tool absorbs the repetitive analyses; you keep the cases that deserve your expertise.
- Disassembly and morphological analysis, resistant to packing, obfuscation and polymorphism
- 3D representation of the threat, to place an unknown file among known families
- Code kinship: which portions the malware borrowed from which families, and in what proportion
- Command line, JSON and IDA exports, custom scripts and knowledge bases
- On-premises analyst workstation: the samples you handle stay with you
06 · ANALYSIS BY OUR EXPERTS
You want this file analysed by an expert.
For the SME, the local authority, the manager with no SOC — “I have a suspicious file, no one to open it, and I would not know how to read a technical report.”
The five situations above assume a team able to act on a verdict. Many organisations have none — and that is no reason to open the file and hope. With GORILLE On-Demand you upload the file: it is analysed by the GORILLE engine, then reviewed by a cybersecurity analyst who sends back a readable report.
- Online upload, all file types, no format restriction
- Analysis by the GORILLE engine, then reviewed by a human analyst
- Danger level stated for every file analysed
- Clear explanation of the results — not a raw export to interpret
- Concrete remediation steps in every report
FRENCH TECHNOLOGY, ANALYSES THAT STAY IN FRANCE
GORILLE is the product of ten years of French public research, carried out at LORIA — a joint research unit of the CNRS, the University of Lorraine and Inria. Cyber-Detect, founded in 2017, holds the exclusive licence to the morphological analysis method and develops the engine in France.
Sovereignty is not only a matter of where the technology comes from, but of what happens at analysis time: that is when your files travel, or do not. In SaaS, they are analysed on a platform hosted in France. On-premises, they simply never leave your infrastructure.
— French research — ten years at LORIA: CNRS, University of Lorraine, Inria
— Exclusive licence — the morphological analysis method is operated by Cyber-Detect alone
— French vendor since 2017 — engine developed and maintained in France
— SaaS hosted in France — your files do not leave national territory
— On-premises — your files never leave your infrastructure
— Institutional customers — French Ministry of Defence, Ministry of the Interior, DGA, NATO
YOUR SITUATION IS NOT ON THE LIST?
Describe it. GORILLE analyses files and recognises the malware inside them; the form — an API call, an analyst workstation, a campaign across the estate — adapts to your constraint, not to our catalogue.