I primarily use Spectra Analyze to check files that come up during the discovery phase, such as open directories, that trigger honeypot alarms, etc.
Disclaimer: I received access as part of my role as a Security Researcher.
I have been using Spectra Analyze for about 1 year now for ~6 hours a week.
Let's start with the interface. There are exactly 2 things that personally bother me.
1. There is no dark mode or I haven't found it.
2. The main dashboard is sometimes overloaded - this also applies to other areas - more on that later.
Otherwise, I must say I find the interface successful. It looks clean, in most cases you immediately see what the status is, and it is thematically well sorted. There are other providers where you feel like you have 10 popups before you find the information. That is not the case here. For some things, like contacted URLs, I would wish for a copy button. That would simplify things a bit more. Otherwise, you have to click 2x more and still get the information - please understand this more as "complaining at a high level."
File Upload
You can upload the data via the GUI or via API. Personally, I have used the GUI now and then, but relatively quickly built an upload script based on the available SDK and now upload 99.9% via API to ReversingLabs.
File Report
On the overview page of the individual file, you immediately see what exactly is going on. Classification, which part (static analysis, dynamic analysis, etc.) rated the file, a graph, network information if available, and much more can be seen at first glance. If you want, you can also get lost in the respective sub-items. Personally, the overview page is usually enough for me.
YARA
What I find pretty good is that I can store my own YARA rules. A "matching" also takes place for files that were uploaded in the past. It is immediately apparent which ones match, you can adjust your rule, etc. - in short, pretty solid.
Support & Feedback
This is the point that surprised me the most. Whether general inquiries or hints about what I didn't like - it was always answered promptly. I was particularly surprised that some requests for possible interface improvements were added within a very short time. I know it differently from other large companies. If I had to give stars, it would be 4.5.
I find the onboarding process with ReversingLabs to be magnificent, as everyone was super involved in addressing our specific needs. They demonstrated high availability and provided very useful tips on how to best utilize our plan. The initial setup of ReversingLabs was extremely easy, making the transition seamless and efficient. Moreover, the process of prioritizing risk management and enriching information with ReversingLabs is highly effective. Overall, I am extremely satisfied with the functionality and support provided, which is why I rate ReversingLabs a perfect 10 and would highly recommend it.
ReversingLabs is a cybersecurity company that specializes in threat detection and analysis solutions. Their platform helps organizations defend against complex cyber threats through advanced file and software analysis. ReversingLabs provides tools for uncovering hidden malware, monitoring file reputations, and conducting deep threat intelligence. Their services are designed to enhance the capabilities of security teams across various industries, improving resilience against cybersecurity challenges.Website: [ReversingLabs](https://www.reversinglabs.com/)
With over 3 million reviews, we can provide the specific details that help you make an informed software buying decision for your business. Finding the right product is important, let us help.