Example report

fabdeploy.exe

product
Fabrikam Deployment Utility 2.1.0
vendor
Fabrikam, Inc. (estimated)
source
Endpoint agent, CON-WKS-4471
assayed
2026-08-03 04:13:02Z
duration
18s
Lens

Or define your ownSection membership is configurable. These three are starting points.

Showing 3 of 18 sectionsShowing 11 of 18 sectionsShowing 18 of 18 sections

Summary readings for this artifact
review61/ 100D44 / 100estimated
verdictfile trustvendor riskattribution
confidence moderate, risk moderate5 weighted factorsidentity estimatedcontent-derived

Verdict

No malicious signals in any examined path, and no signature to establish who published it. The vendor is inferred from the artifact rather than verified. This needs a human decision, and the decision is about provenance rather than about behaviour.

Key findings

  • Unsigned. There is no certificate, so there is nothing to verify a publisher against and no chain to check. Absent, rather than invalid or expired.
  • Vendor inferred as Fabrikam, Inc. from three independent properties of the file itself, version resource, embedded strings, and toolchain artifacts, which agree with one another. That agreement is what produces moderate confidence rather than low.
  • No catalog entry exists for this product under any name. It was never published, so there is nothing to look it up in. A catalog-based tool cannot reach a conclusion here at all.
  • Built with a toolchain several years older than its declared version. Consistent with a long-lived internal tool, and noted because it bears on the maintenance question rather than the safety one.

Recommended actions

  1. Before approvalConfirm with whoever engaged the contractor that this binary is theirs and is current. No property of the file can settle that.
  2. Before approvalRequest signed builds for future releases. A signature moves this from inferred to verified and removes the decision entirely.
  3. On approvalRecord the hash. With no signature and no catalog identity, the hash is the only stable handle on this artifact.
  4. OngoingAny change produces a different hash and no way to distinguish an authorised update from an unauthorised one. Re-analysis on change is the only control available.
Decision4Why it concluded that, and whether to approve

Verdict factors

factorreadingweightdetail
Code signatureattentionhighAbsent. Not invalid, not revoked, absent. There is nothing to verify.
Malicious signalspositivehighNo rule matches in any examined content path. See Analysis coverage for what was and was not examined.
Vendor reputationneutralmediumVendor inferred, not verified. A reputation record cannot be attached to an identity that has not been established.
Software categoryneutralmediumDeployment tooling. Elevated baseline by category, not by finding.
Licence obligationsneutralmediumNo licence declared and none inferable. Contract terms, not file terms.
Terms-of-service postureneutrallowNot applicable to a binary that was never published.

Scores

61/ 100 file trust

dimensionweightscorenote
Malicious signals40%100No matches in examined paths
Code signing20%0Unsigned: no publisher established
Vendor reputation20%40Identity inferred, so reputation is unattachable
Software category15%50Deployment tooling, elevated baseline
Terms-of-service posture5%50Not applicable
Vendor2Who published this, and what corroborates it

Vendor intelligence

D44 / 100 vendor risk · identity estimated · evidence completeness 38%

Identity confidence is graded, not asserted. Every line below is tied to something in the artifact itself: a certificate subject, a declared product string, because a package name is not a vendor.

dimensionweightscorenote
Identity verification25%35Three artifact properties agree; none is authenticated
Security posture25%30No public disclosure process to assess
Code signing15%0Unsigned
Licence compliance15%50No declared licence; governed by contract
Community health10%40No public repository, expected for contractor work
Vendor maturity10%70A registration matching the inferred name exists

Confidence is capped at estimated and cannot rise without an authenticated tie between the artifact and the vendor. Three agreeing but unauthenticated properties lift it above a guess; no number of them makes it verified. A package name is not a vendor, and neither is a resource string.

Evidence

sourcetied tosays
PE version resourceCompanyName field inside this artifactFabrikam, Inc.
Embedded stringsBuild paths and copyright strings in the binaryConsistent with the same company name
Toolchain artifactsRich header and linker markersOne consistent build environment across all sections
Company registrationThe inferred name only, not to the artifactA company of that name is registered, which corroborates nothing about who built this file

Enterprise readiness

Deployment methodCopied into place; no installer
Silent installNot applicable
Update mechanismNone, replaced manually
UninstallNo uninstall entry; deleting the file is the uninstall
Runs as serviceNo
Network listenersNone indicated by imports
TelemetryNone identified
Offline operationYes

Approval readiness

Review, provenance, not behaviour

Conditions

  • Ownership confirmed with the engaging team
  • Hash recorded as the identity of record
  • Signed builds requested for future releases

Rules matched

Signed by verified publisherreview
Minimum trust score ≥ 70review
Known vendor in sanctioned registerreview
No malicious signalsallow
Compliance3Framework posture, obligations, and the limits

Compliance

frameworkmetgapreview
NIST SP 800-53322
SOC 2212
ISO 27001:2022 A.8212
CMMC 2.0112
PCI-DSS v4.0111
HIPAA Security Rule101
GDPR100

Controls

controlstatusnote
SI-7Software integrityNIST SP 800-53gapNo signature, so no integrity mechanism beyond the recorded hash
CM-7Least functionalityNIST SP 800-53metSingle binary, no bundled components
SA-12Supply chain protectionNIST SP 800-53gapProvenance rests on an unauthenticated claim inside the artifact
CM-11User-installed softwareNIST SP 800-53reviewPresent in a machine-wide path with no installer record
CC6.8Unauthorised softwareSOC 2reviewApproval is possible, but the identity being approved is inferred
CC7.1Change detectionSOC 2gapNo signature; change detection depends entirely on hash comparison
A.8.19Software on operational systemsISO 27001:2022 A.8reviewPresent and recorded; provenance incomplete
A.8.30Outsourced developmentISO 27001:2022 A.8gapContractor-supplied with no verifiable link to the supplier

Licence obligations

None declared. Governed by the contract with the supplier, not by anything in the file.

obligationappliesnote
Commercial-use restrictionnoNo terms present in the artifact
AttributionnoNo third-party notices found
CopyleftnoNo copyleft-licensed components identified
Source disclosurenoNot triggered
Patent grantnoNone present

Analysis coverage

What was examined, and what was not. The limits belong next to the decision, not behind it.

Examined

PE structure, sections, imports, resourcesfull
Signature slot, confirmed absent rather than assumedfull
Embedded strings and toolchain artifactsfull
Rule matching across extracted contentfull
Similarity against this tenant’s own historyfull

Not examined

Advisory and vulnerability statusNot assessed. This report describes what the file is and who made it, not what is known to be wrong with the software.
Runtime behaviourStatic analysis only. Nothing here describes what the binary does when executed.
Multi-engine antivirus verdictsMulti-engine antivirus runs on a customer-supplied key by design: the quota and the data-sharing decision stay with you rather than with us. No key is attached to this example, so no engines were consulted.
Supplier confirmationWhether Fabrikam actually produced this file is a question for the engaging team. No property of the artifact can settle it.
Composition4What it is made of, and what identifies it

File overview

TypePE32 executable (console) Intel 80386
FamilyWindows executable
Size4.2 MB
Submitted2026-08-03T04:12:44Z
Completed2026-08-03T04:13:02Z

File identifiers

SHA-2567c1f04ae93b28d6f5041ac7739e2b085d6f31c94a0e75b28cd3f6109e4b7a2d5
SHA-1b2e7419c05da8f3e61c4079b2ad85f3061ce9a44
MD531c9a7e04fd2b86530ae19c7d4f0b285
TLSHT1A237C90D5E4B16F802C39A7E1D6084BC35F7A2E90D14C6B839E5072A4FD16C83B0E29A

Names

Submitted asfabdeploy.exe
Original filenameFabDeploy.exe
Product nameFabrikam Deployment Utility
Internal nameFabDeploy

Nearest in your own history

artifacttlsh distanceseen
fabdeploy.exe 2.0.4222025-11-08
fabcollect.exe 3.0.71182026-03-18

The second match is a different Fabrikam tool. A distance of 118 is weak similarity, shared toolchain rather than shared code, and it appears here as corroborating context, not as evidence.

Technical details

Machinei386
SubsystemWindows console
Compile timestamp2019-03-11T08:47:52Z
Sections5
Entry point section.text
OverlayNone
Base relocationsStripped
ASLR / DEP / CFGDisabled / Enabled / Disabled

Sections

namecharacteristicsentropynote
.textCNT_CODE, MEM_EXECUTE, MEM_READ6.28Ordinary compiled code
.rdataCNT_INITIALIZED_DATA, MEM_READ4.91
.dataCNT_INITIALIZED_DATA, MEM_READ, MEM_WRITE3.44
.rsrcCNT_INITIALIZED_DATA, MEM_READ3.97Version resource only: no icon, no manifest
.bssCNT_UNINITIALIZED_DATA, MEM_READ, MEM_WRITE0.00

Imports

modulefunctionsnote
KERNEL32.dll61
ADVAPI32.dll14Registry and service APIs
MSVCR120.dll22Visual C++ 2013 runtime, consistent with the build date
SHLWAPI.dll6

Signature

StatusAbsent
Certificate tableNot present in the optional header
SubjectNone
CountersignatureNone
ConsequenceNo publisher can be established from the file. Every vendor statement in this report is inference, and is marked as such.

Enrichment

sourceconsultedresult
Certificate transparencynoNot applicableNo certificate to look up.
Company registrationyesA company matching the inferred name is registeredCorroborates that the name exists. Does not corroborate that this company built this file, and does not lift identity confidence above estimated.
Verified vendor factsyesNo record
Public repository healthnoNot applicableNo public repository, expected for contractor-supplied software.
Known-malware hash intelligenceyesNo record for this hashAbsence of a record is not evidence of safety and does not contribute to the verdict.
Community threat-intelligence pulsesyesNo pulses reference this artifactNever sufficient on its own: a single uncorroborated feed does not drive a verdict in either direction.
Licence resolutionyesNo declared licence to resolve
Multi-engine antivirusnoNot consultedMulti-engine antivirus runs on your own vendor key by design: your quota, your data-sharing terms, not ours. That is a deliberate product decision rather than a limitation. No key is attached to this example, so no engines were consulted and no engine result appears anywhere in this report.

Compositionnot shipped

CycloneDX 1.5 output for installer-class artifacts is designed, not shipped. Component discovery works today; the signed SBOM document does not exist yet.

1 components identified, 1 with a resolved licence, 0 unresolved. The executables below install alongside the parent product and are governed software in their own right: an approval of the parent does not cover them.

componentversionpublisherlicencerole
Visual C++ 2013 runtime12.0.40660Microsoft CorporationLicenseRef-Microsoft-CRTStatically linked runtime
Forensics2What it touches, and when

Indicators and behaviournot shipped

ATT&CK technique mapping and D3FEND pairing are designed here at a depth the current pipeline does not reach. Observable extraction is real; the mapping from observable to technique is partly manual today.

Observables

typevaluecontext
PathC:\Fabrikam\build\deploy\Release\FabDeploy.pdbDebug path left in the binary
Registry keyHKLM\SOFTWARE\Fabrikam\DeployReferenced in strings
UNC path\\contoso-fs01\deploy$Default share in configuration strings

Techniques

techniquewhy it is listedcountermeasure
T1112Modify RegistryRegistry APIs imported and a product key referenced in strings. Expected for a deployment tool, and listed so the capability is on the record.Registry change monitoring
T1105Ingress Tool TransferCopies payloads from a file share. This is the tool doing its job; it appears because the capability is indistinguishable from the technique.File transfer monitoring

Technique presence describes capability, not intent. The debug path is the only observable worth acting on, and only because it discloses internal structure.

Timelinenot shipped

Reconstructed from artifact timestamps and analysis events. Ordering across sources is best-effort, clock skew between a build host and an analysis host is not resolved.

wheneventfromconfidence
2019-03-11T08:47:52ZArtifact compiledPE compile timestamp, asserted by the file, unverifiable
2025-11-08T00:00:00ZPrior version analysed in this tenantSimilarity history
2026-08-03T04:12:44ZSubmitted by endpoint agentAgent CON-WKS-4471
2026-08-03T04:13:02ZAnalysis completedAnalysis record

Confidence is struck as fineness, the same unit the register uses. Verified means the timestamp is signed or recorded by us; estimated means it is asserted by the artifact and unverifiable.

More of this

New posts on what a file tells you before you run it: headers, signatures, manifests, overlays, the fields most inventory never reads. Only when there is something worth the write-up.

We intend to offer a tool that does this across every file on an endpoint. You get one message when you can use it.

One field, any address. Those two things and nothing else, and replying to any of it removes you.