Malware analysis EU-developed
GLIMPS Malware Expert
File analysis workspace that combines static and dynamic engines, extracts indicators and malware context, and supports investigation and threat hunting.
By GLIMPS · France
The record identifies an EU developer or development origin. The origin note explains the evidence; current ownership and hosting are recorded separately where established.
At a glance
Recorded facts- Response workflow
- Malware analysis
- Developer or maintainer
- GLIMPS
- Recorded country
- France
- Product model
- Commercial
- Deployment
- Self-hosted / SaaS
- Software license
- Commercial license; full terms not publicly verified
- Upstream status
- Active
- Evidence class
- EU-developed
What the sources establish
Origin noteDeveloped by French publisher GLIMPS; an ANSSI service legal notice independently names GLIMPS as its software publisher in Cesson-Sévigné.
Reported capabilities
- Analyzes submitted files with static, dynamic and hybrid engines.
- Extracts malware families, malicious functions, indicators and ATT&CK mapping.
- Supports YARA rules, retro hunting and MISP/STIX/JSON exports.
Scope and limits
Only Expert is counted; Malware Detect and Kiosk are linked ingestion/user-facing offerings in the same analysis ecosystem. Vendor efficacy figures are not represented as verified results. Full Malware Expert EULA terms were not publicly verified.
Inspect the research evidence 4 source observations
identity / capabilities / deployment
Official product page describes commercial Expert analysis capabilities, exports, YARA, and both on-premises and SaaS delivery.
Read sourceorigin / country
ANSSI legal notice names GLIMPS SAS as the software publisher and lists its Cesson-Sévigné address in France.
Read sourcemaintenance
Vendor product portfolio actively offers Malware Expert and a trial; no discontinuation notice appears.
Read sourcelicense
Vendor documentation requires EULA acceptance to use Malware Expert, establishing license-controlled access. The full EULA rights were not available in the reviewed public documentation.
Read source
This profile summarizes source material. It does not include hands-on security testing, procurement review, or an assessment of fit for your environment.
Capabilities & integrations
Tags record specific documented functions. They do not establish end-to-end interoperability; check the component, edition and version in the source.
No structured capability or integration evidence has been added for this tool in the current pass. This does not establish that a feature is unsupported. Send a documentation link.
Put the tool in context.
Plan suspicious-file intake, static analysis, specialist escalation and a defensible handoff. Compare the documented roles of MWDB Core, Pandora and Karton.
A malware triage workflow for suspicious files