Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Malware analysis is the defensive examination of suspicious software to determine whether it is malicious and understand what it does. Researchers combine inspection of a file without running it with observation of its behavior in a controlled environment. Because malware may conceal or delay its actions, neither a single inspection nor a sandbox run necessarily reveals the whole picture.

What malware analysis is for

Malware analysis helps security teams identify suspicious files, understand their capabilities and support incident response. NIST defines malware as a program covertly inserted into another program with the intent to destroy data, run destructive or intrusive programs, or otherwise compromise confidentiality, integrity or availability. That definition appears in NIST Special Publication 800-83 Revision 1, a guide to preventing and handling malware incidents on desktops and laptops published July 1, 2013.

Analysis is not simply a verdict of “safe” or “malicious.” It gathers evidence about a sample and supports conclusions about its identity and behavior. MITRE D3FEND’s File Analysis description includes examining signatures, metadata, hashes, content patterns and disassembled code. Those clues can help characterize a file, but inspection alone may not show what it does when executed.

Static and dynamic analysis answer different questions

Method Does it execute the sample? What it can reveal Important limitation
Static file analysis No Hashes, metadata, signatures, content patterns and code structure, including disassembly. May not reveal runtime behavior or actions that depend on particular conditions. (MITRE D3FEND, File Analysis)
Dynamic analysis Yes, in a controlled environment Interactions between the program and the system while it runs. The sample may detect analysis conditions, wait, or require a trigger that is absent during the observation. (MITRE D3FEND, Dynamic Analysis; MITRE ATT&CK, Virtualization/Sandbox Evasion T1497)

MITRE D3FEND describes dynamic analysis as examining a program’s interactions with a system while it executes in a controlled environment, such as a sandbox, virtual machine or simulator. Static and dynamic methods complement each other: one examines file evidence without execution, while the other records behavior observed during a run. An observation is evidence about what happened under those conditions, not proof that every possible behavior has been exposed.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

What a sandbox does—and does not do

A sandbox is a restricted, controlled execution environment. The NIST CSRC glossary, attributing its definition to CNSSI 4009-2022, says it prevents potentially malicious software from accessing system resources except those for which it is authorized.

In its malware-handling guidance, NIST describes isolating the application from other applications, limiting access to resources such as memory and the file system, and restoring the sandbox to a known-good state when it is initialized. These controls are intended to constrain what the sample can reach and help contain impact; they do not establish that every route to other systems is blocked. MITRE ATT&CK lists application isolation and sandboxing as a mitigation for untrusted content, including browser content, email attachments and downloaded files in its Application Isolation and Sandboxing M1048 guidance.

Why a sandbox run may miss malicious behavior

Malware can behave differently when it suspects that it is being analyzed. MITRE ATT&CK’s Virtualization/Sandbox Evasion T1497 describes checks for system characteristics, user activity and time-based conditions. A sample might wait for a particular date, time or command before acting, or delay execution beyond the observation window. As a result, a quiet run does not by itself show that a file is harmless.

These limits affect interpretation as well as safety. Researchers distinguish what they directly observed from what they infer, and use multiple forms of evidence where appropriate. Static clues can inform a controlled run; observed runtime activity can, in turn, help focus further examination. No one method is universally sufficient.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

How researchers study suspicious software safely

Safe analysis is a security function, not an experiment to conduct by opening an unknown file on an everyday computer. NIST’s guidance emphasizes a controlled, isolated environment with restricted resource access and a reset to a known-good state. A basic virtual machine or ordinary desktop is not automatically safe merely because it is called a lab, and the reviewed guidance does not guarantee that any sandbox prevents every escape or exposure.

  • Use controlled isolation. Analysis environments are designed to limit the sample’s permissions, system-resource access and contact with other applications or systems.
  • Record the scope of observation. A report should make clear that it describes evidence observed under particular conditions; behavior may depend on triggers or analysis evasion.
  • Reset to a known-good state. NIST describes restoring the sandbox environment on initialization, rather than treating a prior run as a clean baseline.
  • Use qualified incident-response channels for real incidents. If a suspicious sample is part of an organizational incident, follow the organization’s security and incident-response process rather than running it on a personal device. The CISA and MS-ISAC Ransomware Guide describes sandbox behavioral analysis and lists malware-analysis assistance channels; service availability should be checked before relying on a particular channel.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.