Runtime analysis

What the dynamic sandbox detects

In short

Extuno runs each extension or package in an ephemeral, network-segmented micro-VM. The run records every host the code contacts, the payload it sends, the API call behind the request, and the data it tries to steal.

What hides from static analysis?

Static analysis is fast and safe, but it only reads what the package contains. Obfuscation hides the behavior, and remotely hosted code is not in the package at all. Running the artifact settles it. The sandbox records where an exfiltration request goes and what it sends. If the package drains wallets, the approval it asks for shows up. If it mines, the miner starts.

How does Extuno run untrusted code safely?

Each run gets its own micro-VM, destroyed when the run ends. The VM is network-segmented, so untrusted code never reaches the main platform. The sandbox can then run something we already believe is hostile and watch what it does.

What behavior does it capture?

When code exfiltrates data, the sandbox records where it went and what it carried. It also catches remote code execution, credential and cookie theft, clipboard wallet swaps, crypto-mining, and command-and-control beaconing. Each one becomes a finding with the captured evidence.

FAQ

Common questions

Is it safe to run real malware?
Yes, in the right boundary. Extuno executes in an ephemeral, network-segmented micro-VM destroyed after each run, so the analyzed code cannot reach the platform or persist.
What does dynamic analysis catch that static misses?
Obfuscation makes behavior unreadable, and some of it only fires once the code runs. The sandbox records which endpoint the code contacted, what it sent there, and what it downloaded and executed after install.