๐๐ฎ๐ฐ๐ต๐ฒ๐น๐ผ๐ฟ'๐ ๐ง๐ต๐ฒ๐๐ถ๐ - Universitร degli Studi del Sannio Designed and developed an automated malware analysis pipeline to detect undisclosed, potentially harmful behaviours in trusted software (๐ด๐ผ๐ผ๐ฑ๐๐ฎ๐ฟ๐ฒ) - a critical problem in the context of ๐๐ผ๐ณ๐๐๐ฎ๐ฟ๐ฒ ๐๐๐ฝ๐ฝ๐น๐ ๐ฐ๐ต๐ฎ๐ถ๐ป ๐๐ฒ๐ฐ๐๐ฟ๐ถ๐๐. Defined a novel classification framework of ๐ญ๐ฎ ๐๐พ๐๐ถ๐๐ผ๐ฐ๐ฎ๐น ๐ฆ๐ผ๐ณ๐๐๐ฎ๐ฟ๐ฒ ๐๐ฒ๐ต๐ฎ๐๐ถ๐ผ๐๐ฟ๐ (๐๐ฆ๐๐) mapped to the MITRE ATT&CK Enterprise Matrix, covering techniques such as ๐๐๐๐๐ฒ๐บ ๐ฟ๐ฒ๐ฐ๐ผ๐ป๐ป๐ฎ๐ถ๐๐๐ฎ๐ป๐ฐ๐ฒ, ๐ฝ๐ฟ๐ถ๐๐ถ๐น๐ฒ๐ด๐ฒ ๐บ๐ฎ๐ป๐ถ๐ฝ๐๐น๐ฎ๐๐ถ๐ผ๐ป, ๐ฑ๐ฒ๐ณ๐ฒ๐ป๐ฐ๐ฒ ๐ฒ๐๐ฎ๐๐ถ๐ผ๐ป, and ๐ฐ๐ผ๐๐ฒ๐ฟ๐ ๐บ๐ฒ๐ฑ๐ถ๐ฎ ๐ฐ๐ฎ๐ฝ๐๐๐ฟ๐ฒ. Built a Python-based orchestration tool with an ๐ฎ๐๐๐ป๐ฐ๐ต๐ฟ๐ผ๐ป๐ผ๐๐, ๐บ๐๐น๐๐ถ๐๐ต๐ฟ๐ฒ๐ฎ๐ฑ๐ฒ๐ฑ ๐ฎ๐ฟ๐ฐ๐ต๐ถ๐๐ฒ๐ฐ๐๐๐ฟ๐ฒ that automated parallel binary submissions to multiple commercial and open-source sandboxes via REST APIs: - ๐๐๐ฏ๐ฟ๐ถ๐ฑ ๐๐ป๐ฎ๐น๐๐๐ถ๐ (Falcon Sandbox) - static + dynamic analysis on Windows 10/11 - ๐ฉ๐ถ๐ฟ๐๐๐ง๐ผ๐๐ฎ๐น - integrated with CAPA (Mandiant/FLARE), CAPE, and ZENBOX - ๐๐ก๐ฌ.๐ฅ๐จ๐ก - real-time interactive detonation with PCAP and memory dump collection Analysed ๐ฏ๐ฒ ๐ด๐ผ๐ผ๐ฑ๐๐ฎ๐ฟ๐ฒ ๐ฏ๐ถ๐ป๐ฎ๐ฟ๐ถ๐ฒ๐ across ๐ฒ ๐๐ผ๐ณ๐๐๐ฎ๐ฟ๐ฒ ๐ฐ๐ฎ๐๐ฒ๐ด๐ผ๐ฟ๐ถ๐ฒ๐. Results revealed that ๐ญ๐ฌ๐ฌ% of samples exhibited covert reconnaissance and OS-level exploitation behaviours (ESB1, ESB6), demonstrating that widely trusted software, including major browsers and streaming platforms, silently performs actions consistent with malware TTPs in the absence of vendor-declared ๐ฆ๐๐ข๐ ๐ (Software Bill of Materials). Data post-processing and ESB mapping performed with Pandas and Seaborn in Jupyter Notebooks.