Skip to content
Sparkle In Technology

Vulnerabilities live in the binary

So that is where we look. Sparkle In Technology performs dynamic binary code analysis — disassembly, simulated execution, and signature comparison against our own vulnerability database — on the compiled software already running in your estate

SourceGuard · cross-verification workspace
SourceGuard cross-verification workspace, with findings split across Common, SourceGuard, External Source and False Positives
Academic Foundation
6Years of research

at the Hong Kong University of Science and Technology.

Industry Milestone
1stReport

binary-code technology report issued by CAICT in China, 8 Feb 2024.

Strategic Partnership
4Products

in strategic partnership with ASTRI, Hong Kong.

Ecosystem Integration
NativePlugin

Tenable Vulnerability Management plugin, cross-validated findings.

The instrument

A microscope shows you what the eye cannot. We do the same for compiled software

A microscope resolves what is present in a sample. Our engine resolves what is present in a binary — the third-party components inside it, and the published vulnerabilities that attach to them

An optical microscope showing microorganisms in its circular viewfield, shown beside a binaryscope of the same form whose viewfield holds a grid of code with three cells flagged in the critical colour.MICROSCOPEmicroorganisms2A1B9C00E1D3A43DB7086E7A2D5BFFC0BINARYSCOPEbinary code vulnerabilities
Same instrument logic, different subject matter

Technical distinction

Most tools read the label.
We test the ingredients

Static scanners match version strings and file fingerprints. When metadata is incomplete, altered, or simply wrong, that approach reports vulnerabilities you have already patched — and misses the ones you have not

Component extraction versus label matching

Coverage

SOFTWARE STACK

Scanning coverage

One engine across the stack — and, uniquely, all the way down into compiled binaries

BINARY CODEJAVAPYTHONHTMLCSSJAVASCRIPTGATEWAY
INFRASTRUCTURE
80%of a device's code covered

Device coverage

Network infrastructure that conventional agents cannot reach

FIREWALLSWITCHSERVERGATEWAY

Components covered600+ modules

Git
Linux
OpenSSL
Python
Redis
SQLite
systemd
tcpdump and libpcap
urllib3
Vim
Git
Linux
OpenSSL
Python
Redis
SQLite
systemd
tcpdump and libpcap
urllib3
Vim

>95%

Analysis accuracy

<5%

False positive rate

<5%

False negative rate

600+

Modules covered

SourceGuard · security overview
SourceGuard security overview dashboard with health score, asset distribution and vulnerability statistics
Why choose us

Deep analysis, in a platform your team can actually run

Hybrid scanning

Binary dynamic scanning combined with proven conventional methodologies, in one engine

Comparative R&D

Built on six years of research with HKUST, and maintained as a living vulnerability database

Certified first, in China

Our core technology holds the first CAICT report on binary code technology, issued 8 February 2024

Trusted & Supported By

ASTRI
Purplevine IP