OPSWAT · Product
MetaDefender Aether
Layered file analysis helps identify threats that simple scanning may miss.

Zero-day detection · Dynamic analysis
Application
Analyse threats before a file is executed
MetaDefender Aether combines reputation, static analysis, dynamic analysis and signal correlation to provide a consistent verdict on a sample.
It is intended for teams that want to move unknown-file analysis closer to the point where files appear and reduce the number of manual assessments in the SOC.
Key capabilities
Threat reputation
An initial assessment of a file, address or domain helps filter known threat indicators quickly.
Adaptive Sandbox
Dynamic analysis can reveal file behaviour, execution chains and attempts to bypass conventional detection mechanisms.
Signal correlation
Combining several layers helps prioritise samples and provide the security team with context around a verdict.
The exact layers, integrations and deployment model are confirmed for the selected version and environment.
From sample to decision
This example shows how analysis can be included in a file-handling process.
Submit the sample
A system sends a file or address for analysis at a controlled point in the process.
Layered analysis
The sample passes through selected reputation, static and dynamic mechanisms.
Assess the result
The team receives a verdict together with the signals that contributed to the risk assessment.
Apply the next action
Organisational policy determines whether to block, investigate further or release the file.
Where to use the analysis
Email attachments
Unknown attachments can be assessed before they are delivered to the user.
SOC and threat hunting
Analysis results add context to incident handling and the comparison of related samples.
Portals and automation
Analysis can be placed before further processing of files accepted by an application.
Integration with security processes
Before deployment, we define which file types require dynamic analysis, what waiting time is acceptable and how the application handles an inconclusive result.
The design should also cover queues, time limits, sample retention, report permissions and the way events are sent to the SOC tools already in use.
RAMS DATA
Plan analysis for unknown files
We can review where dynamic analysis should run in your environment and how to connect it with the existing file flow.
- Identify entry points for samples.
- Agree response times and decision criteria.
- Select integrations with the SOC process.
Need to assess an unknown file?
Describe the current analysis process and file sources. Together we can identify where an additional detection layer will bring the greatest value.