Catch what disappears.
Some evidence exists for only a moment. We’re exploring ways to capture changing code and memory while the context still matters.
DEPTH / BEYOND THE SURFACEMalware hides.
Look deeper.
Code changes. Execution moves. Evidence fades.
We’re designing CORVUS, a Windows malware sandbox for the questions event logs alone can’t answer.
In planning · Sample analysis is not yet available
A payload unpacks. A process hands off execution. The trail gets harder to follow. Our research starts there: preserve what changes, connect what happens, and make the result explainable.
Some evidence exists for only a moment. We’re exploring ways to capture changing code and memory while the context still matters.
DEPTH / BEYOND THE SURFACEBehavior can cross process boundaries and change form. Our goal is to follow those connections and show the evidence that links one action to the next.
CONTEXT / ACROSS BOUNDARIESA finding should invite scrutiny. We’re designing for evidence you can revisit, reasoning you can examine, and gaps you can see.
EVIDENCE / OPEN TO SCRUTINYEach layer reveals a different part of the story. Our proposed architecture brings them together, from behavior inside Windows to observation beyond the guest.
Which process acted? What did it load? What came next? System events and runtime observations are candidates for connecting those details into a useful account of execution.
Validate access requirements, event fields, and coverage for each Windows build.
Memory changes. Objects disappear. We’re evaluating targeted kernel probes and debugger-assisted capture to preserve the state around a critical action, alongside a record of how observation affected it.
Compare baseline and instrumented environments; record pauses, races, and partial reads.
The hypervisor offers another place to observe. We’re evaluating Xen, DRAKVUF, and LibVMI for external inspection, with Intel PT as a candidate for examining execution paths on supported configurations.
External observation has compatibility and perturbation limits. PT needs matching code and context.
Start with the original observation. Connect it to an action, a piece of content, and a finding. The proposed evidence model keeps facts, inferences, and unknowns explicit, so researchers can challenge the interpretation.
Keep gaps explicit when sources fail. Missing records do not establish that an action never occurred.
Depth is something to demonstrate. Our roadmap moves from a defined research question to a working analysis flow, then tests how much each new perspective adds.
Where we standChoose the behaviors to study, the evidence needed to explain them, and the experiments that will test our approach.
Build a repeatable path from controlled execution to preserved evidence and a readable report, starting with one validated platform.
Test against changing memory, cross-process behavior, and delegated execution. Measure what we capture, what we miss, and the noise we introduce.
Compare new tracing and observation techniques against the baseline. Expand where they produce clearer, more useful answers.
Research tracks may run in parallel. Progress depends on validation; release dates have not been set.
CORVUS is in planning and technical evaluation. This is the vision we’re working toward. Implementation and validation are ahead.
Sample submission and analysis are not available yet, and a release date has not been set. Current work focuses on architecture, technology evaluation, and validation design.
CORVUS is a research project by RhineLab, focused on understanding malware through deeper observation and evidence that can be examined.
Windows PE samples are our initial focus. We’re investigating changing code and memory, execution across process boundaries, and ways to preserve the trail when observation sources fail. Depth, coverage, and explainability guide the work.
Look deeper.
Understand more.