ON THE RECORD
SEPT 2026 / Workplace innovation recognitionJUNE 2026 / Gartner Visionary placement announcedFILE SECURITY / Inspect what ships
COMPANY / CYBERSECURITYTHE SOFTWARE INSPECTORS

ReversingLabs asks the awkward question: what’s inside your software?

A trusted vendor can still ship an untrustworthy file. ReversingLabs takes finished software apart, giving buyers and builders a way to inspect the bargain before they run it.

The update arrives wearing all the right clothes. It comes from a vendor you know. It carries a digital signature. It travels through the usual distribution channel. In December 2020, the SolarWinds compromise demonstrated how comfortably malicious code could inhabit that respectable outfit. The uncomfortable question was whether trust in the supplier had become a substitute for examining the delivery.

THE FILE, PLEASE
  • What it does: inspects finished software and suspicious files for embedded threats and risks.
  • Who buys: software producers, enterprise buyers and security operations teams.
  • The useful distinction: it can examine commercial binaries without asking for source code.
  • The habit to borrow: check the artifact before release or installation, then compare the next version.

ReversingLabs has made a company out of this question. Its starting point is the file itself: the installer, the archive, the compiled application, the container. A vendor’s reputation may begin the conversation. The contents of the package get a vote, too. In a business awash with reassuring paperwork, this is an appealingly literal approach.

01 / The signature that wasn’t enough

On December 16, 2020, ReversingLabs published its analysis of SUNBURST. The researchers described compilation artifacts indicating that SolarWinds Orion source code had been modified to include a backdoor, and delivery artifacts showing that the compromised patch went out through the existing release system. Their account made the build and signing infrastructure central to the attack.

That sequence matters. The attacker did not need customers to abandon their ordinary habits. The ordinary habit - install an authentic-looking update from the expected supplier - carried the threat. For software buyers, provenance and safety suddenly looked less interchangeable. For builders, checking a development pipeline also meant checking what came out of it.

ReversingLabs later became part of SolarWinds’ Secure by Design efforts, a relationship described in the company’s 2021 investment announcement. There is a modest but consequential change of perspective here: the delivered package becomes an object worth investigating, even when the organization behind it is familiar.

02 / Open the box. Then open the boxes inside it.

Co-founders Mario Vuksan and Tomislav Peričin started ReversingLabs in 2009. Vuksan is CEO; Peričin is chief software architect. Their subject is reverse engineering, applied to the tiresome practical problem of understanding files at enterprise scale. The name is unusually candid. These people take things apart.

Tomislav Peričin working at a laptop in ReversingLabs’ Zagreb office
THE PACKAGE OPENERS. Co-founder Tomislav Peričin at work in Zagreb, in the company’s 2016 office archive. A room with a view; a job concerned with what hides underneath.

The underlying engine, Spectra Core, identifies formats, unpacks embedded objects and extracts information about their structure. An archive can contain an installer, which can contain libraries, scripts and resources. The inspection follows that nesting. ReversingLabs develops its own unpackers for supported formats, rather than treating every package as a single opaque blob.

Static analysis performs this work without executing the file. It can expose clues in the code and structure without waiting for a program to reveal itself in a test environment. Dynamic analysis asks a different question by running a sample and observing it. ReversingLabs offers both in its analyst workbench; the methods give investigators different kinds of evidence.

The important commercial consequence is access. A bank buying software seldom receives the vendor’s entire source repository. A binary inspection tool can assess the deliverable anyway. This makes the same technical machinery relevant to people who build applications and people who merely have to live with them.

03 / Four products, four different desks

Spectra Assure handles software supply chain inspection. It checks packages for malware and tampering, builds component inventories, and produces a SAFE report: Software Assurance Foundational Evaluation. The report gives buyers and producers a shared place to discuss findings. An SBOM names components. A risk report helps explain which ones deserve attention and why.

Features depend on the plan. Commercial and proprietary package inspection belongs in the paid Essentials and Enterprise tiers. The Enterprise offering adds capabilities including vulnerability assessment and exposed-secret detection. The distinction matters because a free open-source lookup account is a different service from uploading a complete commercial application for inspection.

SAME FILE. DIFFERENT JOB.
AssureCan we release or deploy this package?
AnalyzeWhat is this suspicious sample doing?
DetectHow do we inspect a stream of incoming files?
IntelligenceWhat is already known about this file or network indicator?

Spectra Analyze is the malware analyst’s workbench. It combines static inspection, a private cloud sandbox, search, relationship graphs and YARA rules. YARA lets investigators describe patterns worth finding in other samples. A verdict becomes more useful when an analyst can inspect its reasoning and hunt for relatives.

Spectra Detect addresses throughput: files arriving through email, web traffic, storage and other enterprise channels. It offers cloud, virtual-appliance and air-gapped implementations. Spectra Intelligence supplies file and network reputation and threat context. The family resemblance is deliberate. The company sells several ways to apply its file knowledge, rather than requiring every customer to become a reverse engineer.

04 / The queue at city hall

One of ReversingLabs’ more revealing customer accounts concerns an unnamed Canadian municipality with roughly 18,000 end users. Its security team faced a backlog of requests to approve commercial software. Reviews were manual, interruption-prone and spread across multiple days. Adding staff was difficult.

CUSTOMER-REPORTED WORKFLOW RESULT
Multiple days15 min

One anonymous Canadian city’s software analysis process. A case result, rather than a universal scan-time promise.

The city used Spectra Assure to inspect packages and shared SAFE reports with suppliers. Findings became specific requests for fixes. Employees requesting software could receive a consistent explanation for an approval, refusal or temporary exception. The company’s case study reports that analysis fell to 15 minutes while labor costs stayed flat.

The lesson worth copying is the sequence: acquire the package, assess it against defined policies, give the supplier actionable findings, and record the decision. Speed comes partly from making the decision repeatable. A scanner feeding an ownerless inbox would leave the organizational problem intact.

The wider customer base includes software producers such as SolarWinds, Crogl and AdriaScan, alongside security providers such as Wirespeed. ReversingLabs says its products are used by 20% of the Fortune 100 and more than 60 cybersecurity companies. Those are company-reported figures, but they explain the market it serves: institutions with many files, complex software and expensive consequences for misplaced trust.

05 / Eight years before the cheque

ReversingLabs says it was self-funded from inception until its November 2017 Series A. That round brought $25 million, led by Trident Capital Cybersecurity and JPMorgan Chase. In August 2021, Crosspoint led a $56 million Series B, with ForgePoint and Prelude participating. The announced purpose of the later investment included expanding sales and marketing.

ReversingLabs co-founder and CEO Mario Vuksan
A LONG LOOK AT A SHORT FILE. Mario Vuksan, co-founder and CEO. ReversingLabs’ first announced venture round came eight years after its founding.

“If you want to survive, your technology has to be solid.”

Mario Vuksan / recalling the company’s journey at Black Hat, 2023

The long wait is more instructive than a tidy origin myth. In a company account of his Black Hat talk, Vuksan described an uneven journey after the 2008 recession and emphasized the product and customers. Years of file inspection preceded the wave of attention around software supply chain attacks. A technical specialization had found a larger purchasing problem.

Today the business combines subscriptions, intelligence services and enterprise relationships. At the time of review, Spectra Assure lists Community access at $0 and Community+ at $500 per month. Essentials and Enterprise require a quote; contracts are annual or multi-year. The published entry price should not be mistaken for the cost of commercial software inspection.

06 / Evidence needs a place to go

ReversingLabs occupies the space between application security, malware investigation and third-party software risk. It competes with some existing inspection approaches and works alongside others. In 2023, Synopsys announced an agreement combining Black Duck’s open-source scanning with ReversingLabs’ inspection of commercial third-party components. The deal treated the capabilities as complementary.

The same logic appears in integrations. GitHub and Jenkins can bring inspection into development workflows; security platforms can consume the resulting intelligence. An October 2025 Microsoft announcement described a Sentinel content pack that enriches incidents with file reputation. Evidence becomes operational when it reaches the system where someone makes a decision.

There are real conditions on the bargain. Spectra Detect documentation offers Fast and Best processing settings, with reduced unpacking or validation for certain formats in Fast mode. Buying throughput involves checking coverage. Likewise, static findings do not answer every question about a running application or its environment. ReversingLabs’ own combination of static and dynamic tools acknowledges the value of multiple views.

The company’s 2026 supply chain report recorded a 73% rise in malicious open-source package detections during 2025. That measures its detections, not every attack in the world. In June 2026 it announced Gartner Visionary placement in software supply chain security; in September it reported inclusion on Fast Company’s workplace innovation list. The quieter reason to pay attention remains the same: familiar software deserves unfamiliar scrutiny.

A buyer can borrow that principle without borrowing the whole platform. Ask for the artifact. Examine the changes between releases. Put somebody in charge of the findings. Trust is easier to defend when you can point to what you inspected.