Current Doc

Automate Malware Analysis Through Our API

Use Browse Docs to switch sections and search the full docs list.

Documentation

Blue Lantern Security Docs

Learn how to use the marketplace, run security tools, and integrate via the API.

Automate Static Malware analysis with the Blue Lantern Security API

In a business setting you likely will not want to leverage the UI every time you need to run static malware checks on a file. Instead, you should leverage Blue Lantern's API capabilities to build an automated workflow to send suspicious files and then make the risk determination about each file automatically.

Prerequisites

  1. A Blue Lantern Security API Key requested from here API Access.
  2. Familiarity with a scipting language and curl commands.

API Call Required to Submit Files for Analysis

The curl for the API call to submit files for analysis looks as below. You will need to provide your API key and file path in the placeholders below in the scripting language you choose. By default, all checks except for ioc extraction will run. Possible checks are included below and as examples in the curl command.

  • check_malicious_strings will check against Blue Lanterns internal strings set to find any matches.
  • check_extract_iocs will extract IOCs (NOTE: this may produce a lot of noise).
  • check_sections will check for sectional entropy to determine if there is potential executable packing in the file.
  • check_yara will run against a set of default yara rules.
  • check_entropy will check will check the entropy of the entire file.
  • check_file_type will check if there is a possible missmatch between the file extension and the detected file type from scanning the file internals.

curl --location 'https://dapi.bluelanternsecurity.io/runs' \
--header 'Authorization: [YOUR API KEY]' \
--form 'tool="STATICMALWAREANALYZER"' \
--form 'checkCost="false"' \
--form 'file=@"[YOUR FILE]"' \
--form 'check_malicious_strings="True"' \
--form 'check_extract_iocs="True"' \
--form 'check_sections="true"' \
--form 'check_yara="true"' \
--form 'check_entropy="true"'
--form 'check_file_type="true"'

On successful submission, you will receive a job ID for checking the status of the analysis and for fetching the results once the analysis complets.

{
    "message": "Requested Analysis Job Created",
    "result": {
        "jobId": "[JOB ID]"
    }
}

NOTE: these files are only processed for static analysis and no other types of analysis. The file itself is kept for no more than a day in our systems. The final reports are kept for no more than one week. These files must be below 4.5 MB in size to work with our API.

Collecting data

The job statis can be checked from the /runs data endpoint by passing the job ID as a path parameter with a GET request:

curl --location 'https://api.bluelanternsecurity.io/runs/[JOB ID]' \
--header 'Authorization: [API KEY HERE]'

The job will not show "COMPLETE" until the results are ready. Example data response is shown below:

{
    "message": "Job run data retrieved",
    "result": [
        {
            "id": "[JOB ID]",
            "user_id": "[YOUR USER ID]",
            "run_start": "2026-03-31 15:03:33.956299+00:00",
            "run_type": "STATICMALWAREANALYZER",
            "run_status": "COMPLETE",
            "run_description": null,
            "run_end": "2026-03-31 15:03:38.238808+00:00"
        }
    ]
}

Once complete, you can fetch the results of the analysis using the POST request as shown in the curl below:

curl --location 'https://api.bluelanternsecurity.io/results' \
--header 'Content-Type: application/json' \
--header 'Authorization: [API KEY]' \
--data '{
    "jobId": "[JOB ID]"
}'

The results data for the static analyzer looks as follows. The details of each result are included in their own section, and will be marked "null" if the check was not active for a particular run. These results can then be used downstream:


{
    "message": "results retrieved",
    "result": {
        "job_id": "[YOUR JOB ID]",
        "filename": "[YOUR FILE NAME]",
        "analyzed_at": "2026-03-17T16:19:49.775451+00:00",
        "status": "Completed",
        "Status": 200,
        "results": [
            {
                "file": "[TMP FILE NAME]",
                "file_size": 85768,
                "file_type": null,
                "yara_matches": [],
                "malicious_strings": {
                    "strings_count": 1431,
                    "ascii_strings_count": 1431,
                    "utf16_strings_count": 0,
                    "red_flags": {}
                },
                "extract_iocs": {
                    "strings_count": 1431,
                    "ascii_strings_count": 1431,
                    "utf16_strings_count": 0,
                    "classified_strings": {
                        ...
                    }
                },
                "sections": {
                    "analysis_mode": "byte_windows",
                    "window_size": 4096,
                    "window_stride": 2048,
                    "total_sections": 3,
                    "reported_sections": 1,
                    "raw_reported_sections": 3,
                    "suppressed_normal": 0,
                    "sections": [
                        {
                            "name": "window_00000",
                            "index": 0,
                            "raw_size": 5107,
                            "virtual_size": 5107,
                            "entropy": 5.856,
                            "entropy_confidence": "full",
                            "severity": "elevated",
                            "anomalies": {
                                "high_entropy": false,
                                "wx_permissions": false,
                                "size_mismatch": false,
                                "nonstandard_name": false,
                                "entry_point_anomaly": false,
                                "zero_raw_size": false,
                                "packer_hint": null,
                                "encoded_blob_pattern": true
                            },
                            "anomaly_count": 1,
                            "offset_start": 0,
                            "offset_end": 5107,
                            "blob_types": [
                                "base64"
                            ]
                        }
                    ],
                    "deduplicated_overlaps": 2,
                    "distribution_note": "Encoded blob patterns detected in 1 windows."
                },
                "whole_file_entropy": 5.85,
                "checks_enabled": [
                    "entropy",
                    "extract-iocs",
                    "malicious-strings",
                    "sections",
                    "yara"
                ],
                "total_cost": 22
            }
        ]
    }
}

Need Help?

Can't find what you're looking for? Reach out and we'll get back to you.

Contact Support