# Malware Analysis Services

> From $30K · Managed Security & Incident Response · https://cisomarketplace.services/services/malware-analysis-services

Specialized security service providing in-depth analysis of suspected malware to understand capabilities, behavior, and impact. Our expert analysis combines static, dynamic, and memory forensics techniques to identify indicators of compromise, attribution details, and remediation strategies.

## In scope

- Static code analysis
- Dynamic behavior analysis
- Memory forensics
- Network traffic analysis
- Anti-analysis technique identification
- Exploit mechanism review
- C2 infrastructure analysis
- Attribution assessment

## Deliverables

- Detailed malware analysis report
- Indicators of compromise (IOCs)
- MITRE ATT&CK mapping
- Tactical remediation guidance
- Strategic defense recommendations
- Detection rule development
- Threat actor profile

## Tiers

### Essential Malware Analysis: $30K

Analysis of one malware family, up to 3 related samples: static and sandboxed dynamic analysis, capability summary, network and host IOCs, and MITRE ATT&CK mapping. One host memory image. 80 analyst hours.

Limits: devices 1, hours 80

Includes:
- Static and dynamic analysis of up to 3 samples
- Memory analysis of 1 host image
- IOC list (hashes, domains, IPs, file and registry artifacts)
- MITRE ATT&CK mapping
- Tactical remediation guidance

Excludes:
- Full reverse engineering of packed or obfuscated code
- Custom detection rule development
- C2 infrastructure and attribution analysis
- Incident response on affected systems

### Advanced Malware Investigation: $50K

Up to 10 samples across up to 2 families with code-level reverse engineering, anti-analysis and exploit mechanism review, C2 protocol analysis, complete IOC set, and custom detection rules. Up to 3 host memory images. 140 analyst hours.

Limits: devices 3, hours 140

Includes:
- Everything in the basic tier
- Code-level reverse engineering including unpacking
- Anti-analysis and exploit mechanism review
- C2 protocol and infrastructure analysis
- Custom host and network detection rules

Excludes:
- Campaign-wide analysis across the environment
- Threat actor profile
- Enterprise-wide detection rollout strategy

### Incident-Based Malware Response: $85K

Malware work tied to an active or recent incident: up to 25 samples, memory and network captures from up to 10 hosts, campaign timeline, threat actor profile, and a detection strategy for the whole environment. 240 analyst hours.

Limits: devices 10, hours 240

Includes:
- Everything in the advanced tier
- Campaign analysis linking samples, hosts and infrastructure
- Threat actor profile and attribution assessment
- Enterprise-wide detection and hunting strategy
- Briefings for the incident response team

Excludes:
- Containment, eradication and system rebuilds
- Full disk forensics of every affected host
- Expert witness testimony

## Terms

Starting price shown is the lowest published tier. A written proposal fixes scope, tier and price before anything is signed. Timeline is set in the SOW.

Scope this engagement: https://cisomarketplace.services/scope?service=malware-analysis-services
