USE CASES

GORILLE analyses files and recognises the malware inside them through morphological analysis: it compares the structure of the code, not its fingerprint. No signature, no hash — which is why it recognises variants no one has seen yet. What that capability changes for you depends on where you place it: when an alert comes in, in the middle of an incident, across the files on your estate, inside your software chain, or on an analyst’s workstation. Six situations, six answers.

WHERE DO YOU START?

Common scope across the three products: all file types — executables, documents and scripts — on Windows, Linux, Android and macOS. Static and dynamic analysis. French technology, developed in France since 2017.

01 · ALERT TRIAGE

Your EDR flagged a file. Is the alert real?

For the SOC analyst — “I have to decide before my shift ends, without missing the serious one.”

The EDR observes a behaviour, but it cannot always name the binary that produced it. You hand it the file: GORILLE Server returns its verdict in under a second — malicious or not, which family, and at what correlation rate with samples already known. The alert stops being a question mark and becomes a documented decision.

  • Verdict and family attribution in under a second, through morphological analysis of the code — no signature, no hash
  • Recognises 0-day variants and polymorphic strains that signature engines let through
  • Identifies the packer, unpacks the file and analyses the code that actually runs
  • Called through the REST API from your EDR, XDR, SIEM or SOAR: direct IOC enrichment, not one more interface
THE PRODUCT THAT ANSWERSGORILLE ServerSaaS or on-premises · REST API · static and dynamic analysis
< 1 sto analyse a file and return its verdictDiscover GORILLE Server ›

02 · INCIDENT RESPONSE

You need to characterise the threat while the incident is running.

For the head of SOC and the CERT — “My analysts are saturated and management is waiting for an answer.”

In a crisis, time goes into manual characterisation, sample by sample. GORILLE takes that share of the work: it names the malware, ties it to a known family, measures which portions of code it shares with other samples, and produces the MITRE ATT&CK & DEFEND matrix of the techniques it carries. Your analysts keep their time for remediation.

THE PRODUCT THAT ANSWERSGORILLE Server, then GORILLE ExpertCharacterisation engine integrated into Orion Malware by Airbus
Up to 80%reduction in MTTRDiscover GORILLE Server ›

03 · HUNTING FOR DORMANT THREATS

Is malware already sleeping in your files?

For the CISO — “What is my real exposure, beyond what the EDR reports?”

A binary dropped on a workstation can wait weeks before it runs. As long as it does nothing, it produces no behaviour: behavioural detection cannot see it. GORILLE Patrol analyses files at rest, in campaigns, and identifies those carrying malicious code — before detonation, not after.

  • Schedulable campaigns across all or part of the estate, static and dynamic
  • Detection on the file at rest, before any execution — so before the behaviour exists
  • Every malware found is named and tied to its family, not merely flagged
  • On-premises analysis: the files on your estate never leave your infrastructure
  • Strengthens the EDR in place instead of replacing it
THE PRODUCT THAT ANSWERSGORILLE PatrolOn-premises · billed per campaign, by number of workstations
90%of market antivirus outpaced on variantsDiscover GORILLE Patrol ›

04 · SUPPLY CHAIN PROTECTION

You need to check deliverables and dependencies before integration.

For the CISO, the CIO and the software vendor — “I control neither the code that comes in, nor what my customers receive from me.”

A supplier’s deliverable, a third-party dependency, the binary coming out of your build chain: every file crossing your organisation is a way in. A digital signature attests to a sender, not to the harmlessness of a payload. GORILLE Server is called through the REST API at whichever point of the flow you want to control, and returns its verdict on each file before it goes through.

THE PRODUCT THAT ANSWERSGORILLE ServerSaaS or on-premises · REST API
< 5%false positives — a production chain cannot absorb noiseDiscover GORILLE Server ›

05 · REVERSE ENGINEERING

You have to disassemble this binary and read its code.

For the reverse engineer and the malware analyst — “Is it precise enough, and does it actually save me time?”

GORILLE Expert disassembles executables, extracts the structure of the code and compares it against millions of samples. Morphological analysis works on the shape of the code itself: it withstands packing, obfuscation and polymorphism. The tool absorbs the repetitive analyses; you keep the cases that deserve your expertise.

  • Disassembly and morphological analysis, resistant to packing, obfuscation and polymorphism
  • 3D representation of the threat, to place an unknown file among known families
  • Code kinship: which portions the malware borrowed from which families, and in what proportion
  • Command line, JSON and IDA exports, custom scripts and knowledge bases
  • On-premises analyst workstation: the samples you handle stay with you
THE PRODUCT THAT ANSWERSGORILLE ExpertOn-premises · annual licence · Windows, Linux, macOS
Millionsof malware samples in the knowledge base for comparisonDiscover GORILLE Expert ›

06 · ANALYSIS BY OUR EXPERTS

You want this file analysed by an expert.

For the SME, the local authority, the manager with no SOC — “I have a suspicious file, no one to open it, and I would not know how to read a technical report.”

The five situations above assume a team able to act on a verdict. Many organisations have none — and that is no reason to open the file and hope. With GORILLE On-Demand you upload the file: it is analysed by the GORILLE engine, then reviewed by a cybersecurity analyst who sends back a readable report.

THE PRODUCT THAT ANSWERSGORILLE On-DemandOnline service · per-file analysis, no installation
48 hto receive a report written by an analystDiscover GORILLE On-Demand ›

FRENCH TECHNOLOGY, ANALYSES THAT STAY IN FRANCE

GORILLE is the product of ten years of French public research, carried out at LORIA — a joint research unit of the CNRS, the University of Lorraine and Inria. Cyber-Detect, founded in 2017, holds the exclusive licence to the morphological analysis method and develops the engine in France.

Sovereignty is not only a matter of where the technology comes from, but of what happens at analysis time: that is when your files travel, or do not. In SaaS, they are analysed on a platform hosted in France. On-premises, they simply never leave your infrastructure.

French research — ten years at LORIA: CNRS, University of Lorraine, Inria

Exclusive licence — the morphological analysis method is operated by Cyber-Detect alone

French vendor since 2017 — engine developed and maintained in France

SaaS hosted in France — your files do not leave national territory

On-premises — your files never leave your infrastructure

Institutional customers — French Ministry of Defence, Ministry of the Interior, DGA, NATO

YOUR SITUATION IS NOT ON THE LIST?

Describe it. GORILLE analyses files and recognises the malware inside them; the form — an API call, an analyst workstation, a campaign across the estate — adapts to your constraint, not to our catalogue.