OPSWAT · Product

MetaDefender Aether

Layered file analysis helps identify threats that simple scanning may miss.

OPSWAT

Zero-day detection · Dynamic analysis

Application

Analyse threats before a file is executed

MetaDefender Aether combines reputation, static analysis, dynamic analysis and signal correlation to provide a consistent verdict on a sample.

It is intended for teams that want to move unknown-file analysis closer to the point where files appear and reduce the number of manual assessments in the SOC.

Key capabilities

Threat reputation

An initial assessment of a file, address or domain helps filter known threat indicators quickly.

Adaptive Sandbox

Dynamic analysis can reveal file behaviour, execution chains and attempts to bypass conventional detection mechanisms.

Signal correlation

Combining several layers helps prioritise samples and provide the security team with context around a verdict.

The exact layers, integrations and deployment model are confirmed for the selected version and environment.

From sample to decision

This example shows how analysis can be included in a file-handling process.

  1. Submit the sample

    A system sends a file or address for analysis at a controlled point in the process.

  2. Layered analysis

    The sample passes through selected reputation, static and dynamic mechanisms.

  3. Assess the result

    The team receives a verdict together with the signals that contributed to the risk assessment.

  4. Apply the next action

    Organisational policy determines whether to block, investigate further or release the file.

Where to use the analysis

Email attachments

Unknown attachments can be assessed before they are delivered to the user.

SOC and threat hunting

Analysis results add context to incident handling and the comparison of related samples.

Portals and automation

Analysis can be placed before further processing of files accepted by an application.

Integration with security processes

Before deployment, we define which file types require dynamic analysis, what waiting time is acceptable and how the application handles an inconclusive result.

The design should also cover queues, time limits, sample retention, report permissions and the way events are sent to the SOC tools already in use.

RAMS DATA

Plan analysis for unknown files

We can review where dynamic analysis should run in your environment and how to connect it with the existing file flow.

  • Identify entry points for samples.
  • Agree response times and decision criteria.
  • Select integrations with the SOC process.

Need to assess an unknown file?

Describe the current analysis process and file sources. Together we can identify where an additional detection layer will bring the greatest value.

Discuss your deployment