Skip to main content
Version: Spectra Analyze 9.8.1

ReversingLabs Auxiliary Analysis

Overview

ReversingLabs Auxiliary Analysis is a static analysis service that provides deeper inspection and enrichment for samples processed by Spectra Analyze. When enabled, it runs additional specialized analysis services and returns detailed results that appear on the Sample Details page under Auxiliary Analysis.

Auxiliary Analysis is configured centrally and can be enabled as part of first-party integrations.

Configuration

For more information about configuring this integration, see Integrations - Static analysis.

Auxiliary analysis reports

Maximum supported file sizeSubmitting only distinct files
100 MiBNot supported

When ReversingLabs Auxiliary Analysis finishes processing a sample, a report with the analysis results is sent to the Spectra Analyze appliance. This report can be accessed from the Sample Details page under Auxiliary Analysis.

The report for this integration includes detailed inspection data, such as:

  • General sample information: basic metadata and file identification.
  • Detected heuristics: specialized static analysis heuristics that identify suspicious patterns and behaviors.
  • ATT&CK information: mapping of detected behaviors to the MITRE ATT&CK framework.
  • Extracted files: list of files extracted during the analysis process, each with its own threat score.
  • IOCs: indicators of compromise discovered during the static inspection.
  • Threat score: a numerical value representing the overall risk of the sample.

The threat score of each file, including the sample and all extracted files, indicates its severity and helps interpret the classification.

ScoreClassification interpretation
- 1000Clean
0 - 299Informational
300 - 699Suspicious
700 - 999Highly suspicious
>= 1000Malicious

Auxiliary analysis services

Auxiliary Analysis combines multiple specialized services, each focused on a particular file type or analysis technique:

Service nameSpeciality
APKayeAndroid APK
AncestryFile genealogy
BatchdeobfuscatorDeobfuscation
CAPAWindows binaries
CharacterizeEntropy analysis
ConfigExtractorIoC extraction
DeobfuScripterDeobfuscation
DocumentPreviewVisualization
EmlParserEmail
EspressoJava
ExtractCompressed file
FlossIoC extraction
FrankenStringsString extraction
JsJawsJavascript
MetaPeekMeta data analysis
OletoolsOffice documents
OverpowerPowerShell
PDFIdPDF
PEWindows binaries
PeePDFPDF
PixAxeImages
SwifferAdobe Shockwave
TorrentSlicerTorrent files
UnpackerUPX Unpacker
ViperMonkeyOffice documents
XLMMacroDeobfuscatorOffice documents