Inside DirtyCBC: how we caught a covert implant hiding in signed softwareRead the analysis
Delphos LabsDelphos Labs
Use CasesBlogAbout UsSign InRequest Access
Use CasesBlogAbout UsSign InRequest Access

Understand any software before you trust it.

Delphos analyzes any file and explains what it actually does, so you can approve software, triage threats, and investigate with confidence.

Malware, vulnerabilities, third-party and supply chain risk, surfaced from any file.

No source code·No signatures·No reverse engineer needed
Request AccessBook Demo
Delphos Lantern
mystery-file.exe
Analyzing
Ask anything about this file

Backed by leading security investors.

DecibelIQTSentinelOne VenturesOutpost VenturesDCVC

"Delphos Labs lets AI see inside previously opaque software, turning reverse engineering into a scalable discipline for finding vulnerabilities and supply-chain backdoors."

In-Q-Tel (IQT)
The risk you can't inspect

Your tools have a blind spot.
Delphos closes that gap.

AI lets attackers find and weaponize vulnerabilities faster than any team can keep up, hidden in the software you trust. Today's tooling inspects too early or late, and isn't built to read any software and explain what it does.

Tool
The gap
Delphos LabsWithout source code
EDR
Sees runtime behavior, only after execution starts.
Runtime behavior
SAST
Needs source code, unavailable for third-party software.
Code-level depth
Sandboxes
Miss dormant and conditional logic, only in specific environments.
Dormant & conditional logic
Delphos LabsWithout source code
EDR
The gap

Sees runtime behavior, only after execution starts.

Runtime behavior
SAST
The gap

Needs source code, unavailable for third-party software.

Code-level depth
Sandboxes
The gap

Miss dormant and conditional logic, only in specific environments.

Dormant & conditional logic
How it works

Analyze any software. Understand its behavior.

Upload any file and Lantern reads the code that actually runs, then analyzes its behavior. Pick a fast triage pass or a full deep run, and chat to classify, investigate, and find mitigations in plain language.

Explainable·Interactive·Automated at scale
DepthTriage for a fast pass, or Full for a deep run.
TypeBehavioral analysis, conversational chat, or custom analysis.
Delphos Lantern
conti.exe
What does this software actually do?

A multithreaded file encryptor that locks data with ChaCha8 under an embedded RSA-4096 key. It deletes Volume Shadow Copies, spreads over SMB, and drops a ransom note, the Conti ransomware.

Destructive and self-propagating, recovery without the operator key is infeasible once it runs.

Use cases

Understand the risk across the software you build, buy, and run.

Reveal what software can actually do, malware, vulnerabilities, tampering, and risky vendor behavior. No source required.

Third-Party Software Risk
Vetting Decision
BLOCKHelios Terminal
terminal emulatornot on allowlist

Acme Corp. blocks terminal emulators and the product is not on the approved-terminal list.

Verify vendor software does what the vendor claims. See hidden logic and risky behavior without source code, so you can approve with confidence.

Supply Chain Security
liblzma 5.6.0-1 → 5.6.0-2
  crc64_resolve()
+ malicious_init()
+ got_patch(auth)
~ ifunc_table[3]

Verify builds and updates by detecting tampering between versions. Delphos identifies the XZ Utils backdoor from the binary, no source or signatures.

Advanced Malware Analysis
libpsl-5.dllMalicious

A DLL sideloading payload. The real code is 3.3 MB, wrapped in 52 MB of junk padding to pad the file to 55 MB and slip past scanners.

Understand what malware does, not just that it’s malicious. Expose stealthy, obfuscated threats and triage unknown files with analyst-grade clarity.

Vulnerability Research
sub_10038a0Exploitable
rbx = arg3 - 1  (underflow)
memcpy(arg2, r14, rbx)
reachable · input-driven
CWE-190 → CWE-787 · OOB write

Surface exploitable weaknesses in software, the reachable paths, unsafe operations, and the exact conditions that trigger them.

35 active CVE disclosures in progress.

Purpose-built vs. general-purpose

LLMs try to do this.
Delphos was built for it.

Generic LLMs like Claude and ChatGPT with MCP servers approximate parts of software analysis with manual setup. Delphos runs its own purpose-built models and a full analysis pipeline, built to analyze any software.

Integrated Tooling
Specialized tools built into the agent, not bolted on.
Training Data
150M+ real-world proprietary records.
Dynamic Emulation
Runs software in a controlled environment, even packed or obfuscated.
Decompilation
High-fidelity reconstruction of software.
Scale

Extend your team,
not your headcount.

A small team can now cover the analysis load that used to take a room of specialists. Analyst-grade understanding at machine speed, with no new hires, no manual reverse engineering, and no sandbox upkeep.

Visibility
XZ Utils
backdoor identified from the binary alone.
Speed
~2 hrs
to analyze ~40 samples end to end.
Coverage
9 of 10
malware samples flagged that 60+ AV engines missed.
SOC 2 Type II

Trusted in regulated and mission-critical workflows

SOC 2 Type II compliant and aligned with NIST 800-171. Built for teams who demand clarity, assurance, and operational rigor where security cannot fail. Deploy on-prem, air-gapped, or hosted.

Security Trust Center
Blog

Novel threats, understood.

Original malware and vulnerability research from Delphos Labs.

DirtyCBC · Linux kernel
DirtyCBC: When Linux Kernel Decrypt-Before-MAC Turns Authenticated Encryption Into a Page-Cache Write

Linux kernel page-cache poisoning via AES-256 chosen-plaintext on the RxGK RESPONSE path.

Read
libpsl-5.dll · Sideloading
Threat Intel: libpsl-5.dll. A Sideloading DLL Padded to 55MB, Undetected by 60+ AV Engines for Six Days

The real payload is 3.3MB. The other 52MB is junk padding, appended to slip past scanners.

Read
ValleyRAT · APT
Threat Intel: ValleyRAT. A Zero-Detection Stager Classified 24 Hours Before Its First Signature

A Chinese-language stager with zero AV detections, pulling a second-stage payload from a remote host.

Read
Common questions

Frequently asked questions

Delphos Labs is an AI platform that analyzes compiled software, the programs that actually run, without source code or symbols, using both static and dynamic analysis. Delphos runs its own purpose-built models and a full analysis pipeline, so it explains what a program does, identifies risks, and returns plain-language findings you can trace back to the analysis behind them. Security leaders and analysts use it to approve software, triage threats, and investigate with confidence before software enters their environment. Delphos analyzes through controlled emulation, never by running software on your systems.

Expose the risks hidden
inside your software

No source code·No signatures·No reverse engineer needed
Request AccessBook Demo
Delphos LabsDelphos Labs

No source code required. No signatures. No blind spots.

Company
About UsBlogSecurity Trust CenterBug Bounty ProgramVulnerability Research Policy
Account
Privacy PolicyTerms of Service
Help & Feedback
Contact SupportEmail Us
Social
LinkedInXGitHub
Copyright © 2026 Delphos Labs Inc.
Compliance & memberships
SOC 2 Type IINVIDIA Inception ProgramFS-ISAC Early Stage Affiliate