● IY SECURITY RESEARCH MALWARE ANALYSIS • THREAT HUNTING ● STATIC + DYNAMIC ANALYSIS MITRE ATT&CK • YARA • SIGMA ● RESEARCH LIBRARY ONLINE DEFENSIVE SECURITY RESEARCH ● IY SECURITY RESEARCH MALWARE ANALYSIS • THREAT HUNTING ● STATIC + DYNAMIC ANALYSIS MITRE ATT&CK • YARA • SIGMA
ADVERSARY RESEARCH • DEFENSE ENGINEERING

We Hunt
What Hides.

IY SECURITY is a cybersecurity research and defense company focused on malware analysis, threat research, VAPT, threat hunting and hands-on security training. We turn adversary behavior into actionable defense.

MITRE ATT&CK•YARA•SIGMA•DFIR•OSINT
0

Threats Analyzed

0

Malware Samples Reversed

0

CVEs Found

0

Clients Protected

01 / Services

Offense informs defense.

From finding vulnerabilities to reverse engineering adversary tooling, our services are built around measurable security outcomes.

01
◈

VAPT

Identify exploitable weaknesses before attackers do.

HOVER TO INSPECT →
VAPT / OFFENSIVE SECURITY

Attack Surface Assessment

  • ▸ Web & API penetration testing
  • ▸ Network & infrastructure testing
  • ▸ Auth / business logic testing
  • ▸ Risk-based remediation guidance

Tools: Burp Suite • Nmap • Nuclei • Nessus • Metasploit

Deliverable: Executive + technical report

02
⌁

Threat Hunting

Hypothesis-driven hunts across endpoints, identity and network telemetry.

HOVER TO INSPECT →
THREAT HUNTING / DFIR

Find the Unknown

  • ▸ MITRE ATT&CK hypothesis hunts
  • ▸ IOC / IOA investigations
  • ▸ Detection engineering
  • ▸ Incident triage & threat intel

Tools: Splunk • Securonix • Cortex XDR • Zeek • MISP

Deliverable: Hunt report + detections

03
⌘

Malware Analysis

Reverse engineer malicious binaries and turn behavior into detections.

HOVER TO INSPECT →
MALWARE RESEARCH

Understand the Payload

  • ▸ Static & dynamic analysis
  • ▸ Reverse engineering
  • ▸ YARA / Sigma engineering
  • ▸ IOC & ATT&CK extraction

Tools: Ghidra • REMnux • YARA • CAPA • x64dbg

Deliverable: Malware report + detections

04
▣

Training

Practical cybersecurity training built around real-world investigation workflows.

HOVER TO INSPECT →
HANDS-ON TRAINING

Build Investigator Mindset

  • ▸ Malware analysis labs
  • ▸ TTP-based threat hunting
  • ▸ SOC / IR investigation
  • ▸ Detection engineering

Stack: Windows • Linux • SIEM • EDR • DFIR

Deliverable: Lab + exercises + certificate

02 / Threat Research Lab

The lab is always hunting.

Malware Families

LAST 30D
Ransomware 31%Trojan 24%Spyware 17%Loader 15%Other 13%

Threats Detected

7 DAY TREND
Telemetry: SIEM + EDRDetection pipeline: LIVE
IY SECURITY / RESEARCH PIPELINE

Dynamic Analysis Console

● RESEARCH MODE
PUBLISHED ANALYSIS

Latest Research

LOADING...

03 / Intelligence

Research & field notes.

[MALWARE ANALYSIS]

Inside a Modern Loader: From Dropper to C2

A practical walkthrough of static triage, execution flow and network indicators.

30 SEP 2026 • 8 MIN READ
[TTP]

Hunting PowerShell Without Chasing Noise

Building behavior-focused hypotheses around command and scripting activity.

26 SEP 2026 • 6 MIN READ
[DFIR]

A Field Guide to Suspicious Windows Persistence

Registry, scheduled task and service artifacts investigators should correlate.

20 SEP 2026 • 10 MIN READ
[VAPT]

API Attack Surfaces: What Automated Scanners Miss

Where business logic, authorization and workflow testing become critical.

15 SEP 2026 • 7 MIN READ
[MALWARE ANALYSIS]

YARA Rules That Survive the First Mutation

Designing resilient behavioral and structural signatures for malware families.

08 SEP 2026 • 9 MIN READ
[TTP]

From IOC Hunting to Adversary Hypotheses

Moving from known indicators toward repeatable behavior-based detection.

01 SEP 2026 • 8 MIN READ

04 / Training

Learn by doing.

COURSE 01

Practical Malware Analysis

Static triage, dynamic analysis, reverse engineering and detection creation.

6 WEEKS • HANDS-ON LAB

PE triage → strings & imports → Ghidra → debugging → sandboxing → YARA → ATT&CK mapping → reporting.

Enroll Now
COURSE 02

TTP-Based Threat Hunting

Build hunt hypotheses from ATT&CK techniques and turn telemetry into detections.

4 WEEKS • SOC LAB

Threat intel → hypotheses → ATT&CK → SIEM queries → endpoint telemetry → investigation → Sigma engineering.

Enroll Now
COURSE 03

SOC & Incident Response

Practical alert triage, evidence collection, containment and post-incident detection.

5 WEEKS • DFIR LAB

Alert triage → log analysis → endpoint investigation → containment → evidence → timeline → lessons learned.

Enroll Now

05 / Contact

Let's secure what's next.

Need a security assessment, threat-hunting engagement, malware analysis or a practical training program? Tell us what you're working on.

EMAIL
hello@iysecurity.com
FOCUS
Malware • Threats • VAPT • Hunting • Training