Back En.Ilsole24Ore A new anti-malware platform is launched to protect data sovereignty
The Italian company DEAS is taking part in CyberDSA in Kuala Lumpur, presenting Heimdall-sandbox, a platform for the dynamic analysis of malware, developed entirely in Italia: an environment in which to run suspicious samples, observe their behaviour and conduct investigations whilst keeping the entire process offline. Ranzato: “Italian technology competes at the highest levels, just as it does in other sectors”
How the sandbox works
Hybrid wars from the Mediterranean to the Indo-Pacific and new cyber-attack technologies. At the heart of it all: data sovereignty and the fight against malware. The Italian company DEAS Cyber+ took part in CyberDSA 2026 in Kuala Lumpur, one of Asia’s leading events dedicated to cyber defence, digital security, artificial intelligence and the protection of critical infrastructure. This year’s edition is structured around three key themes – Secure AI, Digital Trust and Data Sovereignty – and brings together institutions, industry, defence organisations and experts from numerous countries. The company, founded by Stefania Ranzato , showcased Heimdall-Sandbox at the event – a platform for dynamic malware analysis, developed entirely in Italia: an environment in which to run suspicious samples, observe their behaviour and conduct investigations, whilst keeping the entire process offline and under the control of the organisation using it.
How the sandbox works
The principle is simple: faced with malware that is increasingly capable of concealing its behaviour, simply reading a file without executing it is no longer sufficient. To find out what a sample does, it must be run in a controlled environment and everything it interacts with must be observed. The platform allows the sample to be executed within isolated, recoverable sandboxes and its execution to be observed from two perspectives simultaneously: that of the system – looking at processes, files, the network and memory – and that of the sample itself – examining what it loads, modifies, decrypts or attempts to . The analyst interacts with the environment in real time and can pre-programme the sandbox’s responses and configurations. At the heart of the technology is AlluQL : the analyst queries the collected events; over 700 detection rules mapped to the MITRE ATT&CK framework are applied; and the analyses are automated. The observed behaviour is thus mapped to a taxonomy used by SOCs, CERTs and security authorities, making the techniques and behaviours identified during the analysis immediately comprehensible. A unified investigation console also reconstructs the behaviour across multiple temporal representations, including three-dimensional visualisations, whilst REST APIs and a dedicated MCP server enable AI agents and other components of the security ecosystem to use the sandbox as a tool .
“Our country boasts top-level expertise and can export not only products, but also technological capabilities, knowledge and security. It is a ‘Made in Italy’ that is less visible than the traditional one, but increasingly strategic,” emphasises Stefania Ranzato . The challenge lies in a market where cybersecurity, artificial intelligence and information management are becoming increasingly interconnected. “Cybersecurity and artificial intelligence will be among the key markets in the coming years. The challenge for Italia is to transform our areas of excellence into global leaders, whilst retaining expertise, intellectual property and industrial capacity within the country . The interest coming from abroad confirms that there is an international demand for Italian technology, even in the most advanced sectors of security,” concludes Ranzato .
The central issue therefore remains that of data sovereignty. A suspicious sample may contain documents, credentials, internal addresses and information the affected organisation. For this reason, it is important that the analysis is carried out without the use of cloud-based components and without the sample or its artefacts leaving the premises: a requirement that is particularly relevant for the defence sector, critical infrastructure and organisations handling strategic information.
Notizie e approfondimenti sugli avvenimenti politici, economici e finanziari.
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
