Unknown Cyber Inc.
Malware genomics platform using automated deep static analysis and code-lineage comparison to identify unseen malware, variants, and supply-chain tampering.
Visit Website ↗Overview
Unknown Cyber’s technology traces back to DARPA’s Cyber Genome Project, and the company positions its platform around “malware genomics” — automated deep static analysis and byte-level/function-level code comparison rather than reliance on signatures or observed runtime behavior alone. Its Malware Lab, JUCY genomic sandbox, and Software Scan products are built to identify previously unseen malware, code lineage, and software supply-chain tampering, including variants that may evade conventional detection.
The platform automates work that traditionally requires expert reverse engineering — accelerating malware triage and attribution, extracting indicators, and generating YARA detection rules — with DFIR workflows and portable/on-premise deployment options. Unknown Cyber is an In-Q-Tel portfolio company with DARPA-related government R&D funding and reports more than 100 clients worldwide.
Innovation Matrix Assessment
Unknown Cyber has extended its underlying genomic analysis into multiple operational products including Malware Lab, JUCY Sandbox, Software Scan, automated YARA generation, DFIR workflows, and portable/on-premise deployments.
The platform is designed to automate work normally requiring reverse engineering, accelerate malware triage and attribution, extract indicators, and generate detection rules — analyses that can take expert teams substantial time are described as reduced to automated workflows measured in minutes.
Unknown Cyber is an In-Q-Tel portfolio company with DARPA-related government R&D funding and states more than 100 clients worldwide. These are meaningful signals, though customer count, recurring revenue, and retention should be independently validated before treating them as final.
Rather than building a better sandbox, Unknown Cyber examines malware's underlying functional code lineage and compares that genomic representation at scale — potentially identifying variants even when their outward appearance or behavior changes.
Published examples cover supply-chain analysis, malware-family correlation, fileless malware, and a Salt Typhoon/Snappybee-related case in which its analysis reportedly isolated malicious code inserted into an otherwise highly similar software binary. Especially strong performance claims should be independently validated as part of a formal Matrix review.
Polymorphic malware, zero-days, software supply-chain compromise, fileless malware, and AI-generated malware variants make scalable code-level analysis strategically relevant over the coming years — the underlying problem is likely to become more important, not less.
Why CISOs Should Care
Unknown Cyber potentially compresses highly specialized malware reverse-engineering and attribution work into an automated, scalable workflow.
What Makes It Different
Rather than relying solely on malware reputation, signatures, or observable execution behavior, its technology analyzes and correlates functional code at a deeper level — asking what the code actually is, not just what it looks like or does.
The Matrix Verdict
90/100 — TRANSFORMATIONAL INNOVATOR
90/100 — Transformational Innovator. A differentiated approach with unusually strong scores in Category Disruption, Real-World Efficacy, and Enduring Relevance. Unknown Cyber is attempting to change malware detection from recognizing what malicious software looks like or watching what it does, to understanding what the code actually is.
Editorial Note: Claims vs. Verified Findings
Cyber Defense Genius distinguishes vendor-provided claims from independently verified Matrix findings. Claims such as detection percentages, specific competitor comparisons, or "zero false positives" receive full editorial credit only after supporting evidence, customer validation, or independent testing. The 100+ clients figure and specific case studies (e.g. the Salt Typhoon/Snappybee example) are vendor-published and should be independently corroborated.
Sources
Alternatives to Unknown Cyber Inc.
Horizon3.ai
Autonomous penetration testing company whose NodeZero platform self-attacks networks without persistent agents, aiming to replace annual manual pentests…
Pentera
Automated security validation platform that safely runs real attack techniques against production environments to prove which exposures are…
CrowdStrike
Publicly traded endpoint and cloud security leader whose Falcon Exposure Management module extends its platform into AI-driven vulnerability…
Reality Defender
Deepfake and synthetic media detection company offering real-time detection across voice, video, image, and text for enterprises and…
Recorded Future
Threat intelligence platform aggregating open, dark web, and technical sources into real-time risk scoring; acquired by Mastercard in…
Mandiant (Google Cloud)
Incident-response and threat-intelligence firm founded by Kevin Mandia, acquired by Google Cloud in 2022 for $5.4 billion.