Skip to content
Sparkle In Technology

Vulnerabilities live in the binary

So that is where we look. Sparkle In Technology performs dynamic binary code analysis on the compiled software running on your systems. Our engine disassembles that software and simulates how it runs. What comes out is matched against our vulnerability database.

Our platform · cross-verification workspace
Our platform cross-verification workspace, with findings split across Common, Our platform, External Source and False Positives
Academic Foundation
6Years of research

with the Hong Kong University of Science and Technology.

Industry Milestone
1stReport

on binary code technology issued by CAICT, February 2024.

Strategic Partnership
4Products

developed with ASTRI in Hong Kong.

Ecosystem Integration
1stHong Kong Company

to join Tenable OPEN as a technology partner.

The instrument

A microscope shows you what the eye cannot. We do the same for compiled software.

A microscope resolves what is present in a sample. Our engine resolves what is present in a binary. It names the third-party components inside, and the published CVEs recorded against them.

An optical microscope showing microorganisms in its circular viewfield, shown beside a binaryscope of the same form whose viewfield holds a grid of code with three cells flagged in the critical colour.MICROSCOPEmicroorganisms2A1B9C00E1D3A43DB7086E7A2D5BFFC0BINARYSCOPEbinary code vulnerabilities
Same instrument logic, different subject matter

Technical distinction

Most tools read the label,
We test the ingredients

Static scanners match version strings and file fingerprints. When that metadata is incomplete, altered or wrong, they report vulnerabilities you have already patched, and miss the ones you have not.

Component extraction versus label matching

Coverage

SOFTWARE STACK

Scanning coverage

One engine across the stack, all the way down into compiled binaries.

BINARY CODEJAVAPYTHONHTMLCSSJAVASCRIPT
INFRASTRUCTURE

Device coverage

The code inside firewalls, switches and gateways, which agent-based tools cannot inspect.

FIREWALLSWITCHSERVERGATEWAY

Components covered

Git
Linux
OpenSSL
Python
Redis
SQLite
systemd
tcpdump and libpcap
urllib3
Vim
Git
Linux
OpenSSL
Python
Redis
SQLite
systemd
tcpdump and libpcap
urllib3
Vim

>95%

Analysis accuracy

<5%

False positive rate

<5%

False negative rate

600+

Modules covered

Our platform · security overview
Our platform security overview dashboard with health score, asset distribution and vulnerability statistics
Why choose us

Deep analysis, in a platform your team can run

Hybrid scanning

Binary dynamic scanning and established conventional methods, combined in a single engine.

Comparative R&D

Built on six years of research with HKUST, and backed by a vulnerability database we keep current.

First report in China

CAICT issued its first report on binary code technology in February 2024. Our core technology was the subject.

Technology Partnership

Our platform integrates directly with Tenable One Vulnerability Management through a plugin. We are Tenable's first Technology Partner in Hong Kong.

Technology Partner

Tenable logo

Trusted & Supported By

ASTRI
Purplevine IP