Cases

Case Studies.

Real security-analysis and engineering tasks, all done with AVL Code and the Landi model — from sample reversing and traffic triage to building detection tools.

Session replays & reports are original records in Simplified Chinese · Built with AVL Code + the Landi model

User Cases

1

Real-world cases from users’ own business scenarios, delivered with AVL Code.

Team Showcase

20

Real security-analysis and engineering tasks completed by the Antiy team with AVL Code.

#021 · Sample Analysis ·

Analysis of a Malicious Loader Disguised as a WinRAR Installer

To thoroughly analyze a malicious-loader-to-remote-control-backdoor chain disguised as a WinRAR installer, analysts drove AVL Code with a single natural-language instruction, closing the loop from malicious sample to a complete analysis report.

Malicious LoaderWinRAR DisguisePowerShell BackdoorScheduled-Task PersistenceHosts Hijacking
View case
#020 · Sample Analysis ·

Analysis of a Disguised-Service Cryptocurrency Miner (XMRig Variant)

To thoroughly analyze a cryptocurrency-mining trojan disguised as a system service, analysts drove AVL Code with a single natural-language instruction, closing the loop from malicious sample to a complete analysis report.

Mining TrojanXMRigService MasqueradeScheduled-Task PersistenceHTTP/WebSocket
View case
#019 · Sample Analysis ·

Analysis of a Miner-Worm

To thoroughly analyze a compound cryptomining-worm threat, analysts drove AVL Code with a single natural-language instruction, closing the loop from malicious sample to a complete analysis report.

Miner-WormMoneroSMB WormIPSec BypassYARA
View case
#018 · Sample Analysis ·

Analysis of a Malicious Loader (cspsvc.exe)

To thoroughly analyze a malicious-loader threat, analysts drove AVL Code with a single natural-language instruction, closing the loop from malicious sample to a complete analysis report.

Malicious Loader.NETWindows ServicePowerShellPersistence
View case
#017 · Sample Analysis ·

Analysis of the tflower Ransomware

To thoroughly analyze a ransomware threat, analysts drove AVL Code with a single natural-language instruction, closing the loop from malicious sample to a complete analysis report.

RansomwaretflowerWindows SecurityEncryption AnalysisIOC Extraction
View case
#016 · Sample Analysis ·

Analysis of a CryptoLocker Ransomware Variant (Rapid/Djvu)

To thoroughly analyze a ransomware threat, analysts drove AVL Code with a single natural-language instruction, closing the loop from malicious sample to a complete analysis report.

RansomwareCryptoLockerRapid/DjvuWindows SecurityYARA
View case
#015 · Sample Analysis ·

Analysis of an Android Remote Access Trojan (RAT)

To thoroughly analyze an Android remote-access-trojan threat, analysts drove AVL Code with a single natural-language instruction, closing the loop from malicious sample to a complete analysis report.

Android RATBanking TrojanAccessibility AbuseMobile SecurityYARA
View case
#014 · Sample Analysis ·

In-Depth Analysis of the Yayaya Mining Trojan and Its Kernel Rootkit

To thoroughly analyze a Linux mining-trojan threat, analysts drove AVL Code with a single natural-language instruction, fanning out three parallel sub-agents to close the loop from malicious sample to a complete analysis report.

Mining TrojanLKM RootkitDiamorphineLinux SecurityMITRE ATT&CK
View case
#013 · Supply-Chain Verification ·

Verifying the Grok Build CLI Repository-Upload Claim

Security researcher cereblab reported that Grok Build CLI v0.2.93 uploads an entire code repository, together with its full git history, to xAI cloud storage. Analysts used AVL Code to statically analyze the offline installer for that version, checking the claim against the code inside the client binary item by item.

Grok Build CLISupply-Chain VerificationData ExfiltrationTaint AnalysisStatic Analysis
View case
#012 · Sample Analysis ·

Multi-Agent Parallel Analysis of an Android Banking Trojan

Analysts used AVL Code — driven by the Landi N2.5 model — to run a multi-agent parallel analysis of a malicious Android app, confirming it as an Android banking trojan masquerading as a legitimate application.

Android Banking TrojanPayment PhishingOverlay AttackOTP TheftMulti-Agent Analysis
View case
#011 · Compliance Check ·

MLPS 2.0 Compliance Check Driven by a Baseline-Scanner MCP

A security-ops engineer used AVL Code to invoke antiy-baseline-scanner-mcp with a single natural-language instruction, automatically running a full MLPS 2.0 Level-3 (S3A3G3) security compliance check on a Windows host.

MLPS 2.0Baseline CheckMCP ProtocolCompliance AutomationCompliance Report
View case
#010 · Traffic Analysis ·

Network Fault Localization in a Complex Business System

To pin down the root cause of a network fault in a complex business system, engineers drove AVL Code with natural-language instructions — a full intelligent loop from 2.2GB of traffic captures to a fault-localization report.

Network Fault LocalizationTraffic AnalysisRoot-Cause AnalysisComplex Business SystemsLarge-Scale Traffic
View case
#008 · Security Ops & Inspection ·

Automated Inspection and CVE Scanning for Antiy IEP EPP

With one open-ended natural-language instruction, an ops engineer had AVL Code run the whole loop: SSH into the host, inspect Antiy IEP EPP, check service status, scan for CVEs, redact sensitive data and generate an HTML report.

SSH AutomationProduct InspectionCVE ScanningFault Self-HealingThreat IntelligenceReport Automation
View case
#007 · R&D & Testing ·

Smart Installation and Setup of cve-mcp-server

To automate MCP service configuration, a developer gave AVL Code a single open-ended natural-language instruction — an end-to-end intelligent loop from vague prompt to working MCP service.

MCP IntegrationIntelligent AgentFault Self-HealingThreat IntelligenceCVE TriageOps Automation
View case
#006 · Security Tooling ·

iOS Exploit-Kit Response and Security Check Tool

To support the MIIT with a rapid response to an iOS exploit-kit security incident, engineers used AVL Code to build a zero-dependency HTML detection tool in record time.

iOSExploitDetection Tool
View case
#005 · Sample Analysis ·

Darkhotel JPEG Steganography Sample Analysis

Darkhotel is an APT group with an East Asian background. Analysts ran fully static analysis on a suspected sample with AVL Code, reconstructing its multi-stage information-theft attack chain end to end.

SteganalysisJPEGDarkhotelAPTWOW64
View case
#004 · Traffic Analysis ·

IRC Botnet Traffic Capture Analysis

Working from a captured IRC botnet traffic dump, analysts used AVL Code to reconstruct the full C2 communication picture through protocol-level behavioral analysis.

Traffic AnalysisIRC BotnetC2 Detection
View case
#003 · Behavioral Analysis ·

EDR Behavioral Alert Chain Reconstruction

An EDR platform raised a PowerShell alert. Engineers dug deeper with AVL Code, reconstructing a five-level process call chain and uncovering a DNS covert channel and LotL techniques.

EDRPowerShellDNS TunnelingMITRE ATT&CK
View case
#002 · Sample Analysis ·

In-Depth Analysis of the fast16 Malware

fast16 is a piece of malware with destructive capability. Analysts used AVL Code for purely static analysis, fully reconstructing the attack chain and delivering a detection tool plus YARA rules.

Reverse EngineeringPE AnalysisYARAThreat Detection
View case
#001 · R&D & Testing ·

NetAdmin Console Compatibility Analysis

NetAdmin is a support tool for network administrators. Test engineers used AVL Code to run a full-stack compatibility analysis across the entire product.

Compatibility AnalysisTechnology AssessmentSOP
View case