Netskope LogoNetskope Logo
  • Security Services
  • AI Services
  • Networking Services
  • Analytics Services
  • Integrations
  • getting-started.svgGetting Started
    • Support
    • Community
    • Netskope.com
    © 2026 All Rights Reserved. Netskope Inc.
    Home
    Threat Protection
    Advanced Threat Protection
    Advanced Heuristic Analysis

    Advanced Heuristic Analysis

    Note

    You must have the Advanced Threat Protection license to use Advanced Heuristic analysis.

    Attackers are increasingly using layers of obfuscation and packing to evade conventional detection and analysis tools. Netskope recursively unpacks files and extracts internal objects to make them fully available for analysis. You can use advanced statical analysis on binary files to deeply analyze binary file components without executing them.

    The Netskope Advanced Heuristic engine:

    • Detects signature-less malware.
    • Conducts static analysis without file execution.
    • Scans binary files to identify indicators of malicious activity.
    • Analyzes files against 3,000+ threat indicators across a wide range of binary file types, including Windows, Mac OS, Linux, iOS, Android, and supports over 3,500 file format families.
    • Decomposes, unpacks, and de-obfuscates files to extract all objects for analysis.
    • Leverages its advanced engine to rapidly detect evasive, zero-day malware.

    Viewing Advanced Heuristic Analysis

    To view the Netskope advanced heuristics analysis:

    1. Go to Incidents > Malware.

    2. In the Files tab, click the File Name of the file you want to view advanced heuristics analysis.

    3. Click Netskope Advanced Heuristics Analysis to see the following information:

      • File Details: Shows certificate, signer, issuer, algorithm, and container file information. You can also:

        • Click Total to see archive child sub-components and files.

        • Click See Malicious Files to see which of the sub-components and files are malicious.

      • Network References: Shows domain information.

      • Indicators: Shows activity of malicious behavior.

      • Key Capabilities: Shows what the malware is capable of doing.

    In this Topic
    • Advanced Heuristic Analysis