Erfahren Sie mehr über Benny Czarnys Buch „Cybersecurity Upside Down“

Mehr erfahren
Wir verwenden künstliche Intelligenz für Website-Übersetzungen, und obwohl wir uns um Genauigkeit bemühen, kann es sein, dass sie nicht immer 100%ig präzise sind. Wir danken Ihnen für Ihr Verständnis.

MetaDefender™ Cloud Adds Unified Zero-Day Detection with MetaDefender™ Aether

MetaDefender™ Aether brings richer intelligence to every Sandbox inspection, including Threat Reputation, Scoring, and Hunting
Von Bianca Bobirca, Produktmarketing-Managerin
Jetzt teilen

Key takeaway: MetaDefender™ Aether expands MetaDefender™ Cloud’s sandboxing into a five-layer detection pipeline that combines reputation, AI-driven static analysis, dynamic analysis, threat scoring, and threat hunting. The integration leads to richer insights, risk-scored verdicts, and broader context around malicious files and campaigns.

Starting October 1st, MetaDefender™ Aether will be fully integrated into MetaDefender™ Cloud; the integration pulls richer insights and intel from an infected file, once it’s detected by the sandbox.

The sandboxing step now adds reputation context, pre-execution analysis, a scored verdict, and campaign-level intelligence around it.

What is MetaDefender Aether

MetaDefender Aether is OPSWAT’s AI-powered malware detection solution designed to catch known, unknown, evasive, and Zero-Day file-based threats. MetaDefender Aether unifies Threat Reputation, Predictive AI, Adaptive Sandbox, Threat Scoring, and ML-powered Threat Hunting into a single verdict, empowering SOC teams to act faster, avoid unnecessary alerts, and prioritize their resources across different environments.

MetaDefender Aether Delivers Richer Insights and Additional Context for Threat Hunters and SOC Teams

With MetaDefender Aether integrated, sandbox detonation results in MetaDefender Cloud are enriched with threat reputation, pre-execution prediction, threat scoring, and threat hunting with attribution from MetaDefender Aether's five-layer pipeline.

Every file submitted to MetaDefender Cloud now moves through this pipeline, and the output is one consolidated verdict instead of five separate reports an analyst has to piece together by hand. Here's what MetaDefender Aether adds to the analysis:

Ebene

Aktion

Ergebnis

1. Bedrohungsbewertung

Checks files, URLs, IPs, and domains against reputation data that updates continuously, online or offline

Catches reused malware and known attacker infrastructure before any deeper analysis is spent on them; forces attackers to burn indicators faster.

2. Static Analysis

Predictive Alin AI examines files pre-execution, without inspection. It looks at file structure, embedded objects, scripts, and payload characteristics to predict malicious intent in milliseconds, with no signatures and no detonation required.

Catches malware that has never been seen before and malware that mutates on each infection.

3. Dynamische Analyse

Uses instruction-level emulation to force evasive code paths to execute, surfacing behavior logs, registry changes, dropped files, process injection, C2 callbacks, and anti-analysis techniques

Delivers the deep behavioral evidence that reputation and static checks can't produce on their own. Helps analysts document attacks and enrich threat intel.

4. Bedrohungsbewertung

Combines evidence from reputation, static, and dynamic analysis, including execution flow, obfuscation, persistence techniques, and MITRE ATT&CK / Malware Behavior Catalog mappings, into one confidence-based risk score

Turns separate outputs into a single prioritized verdict an analyst can act on right away. Real-time severity scores preserve resources and reduce alert noise.

5. Threat Hunting

ML-powered similarity search and Threat Pattern Correlation connect an unknown sample to known malware families, infrastructure, tactics, and related variants

Moves detection from a single flagged file to campaign-level intelligence. Reveals malware strains, forcing attackers to rethink their tools, infrastructure, and tradecraft

What This Means for MetaDefender Cloud Users

Aether introduces a new workflow that customers can use directly through both the UI dashboard and API. Files can be submitted through either interface, while the sandbox continues to perform the detonation work it has always done. Behind the scenes, the workflow brings changes to what the analysis reveals and how those results are surfaced.

Risk-Scored Verdict/ File instead of Raw Output

Once the sandbox flags a file, the Threat Scoring layer correlates it with the reputation and static findings into one confidence-based risk score. An analyst gets a scored verdict instead of raw sandbox output to interpret by hand.

Campaign-Level Insights

Threat Hunting correlates the flagged file and connects it to known malware families, infrastructure, and campaigns. A detection that used to end with "this file is malicious" now extends into "this file belongs to this family, uses these tools, and matches this pattern of activity."

What Analysts Receive

The pipeline outputs a consolidated verdict with a confidence-based risk score, backed by both static and runtime indicators. That verdict comes with MITRE ATT&CK and Malware Behavior Catalog mappings, unpacked payloads, and extracted malware configurations. An analyst reviewing a flagged file gets the reasoning behind the score along with the score itself, not just a number.

None of these need a separate tool or a second login. They show up in the same MetaDefender Cloud dashboard analysts already use.

Integration and Ecosystem

The integration is built in the platform. It supports MetaDefender Cloud's public APIs for files, hashes, and URLs, external REST APIs for file, URL, IP, and domain submissions, and direct connections to SIEM and logging platforms through API or event export. It plugs into CI/CD tooling, repositories, SDKs, and plugins, and it works with SOAR orchestration platforms for automated response.

Access Model

Full access to MetaDefender Aether is granted by an OPSWAT representative as part of package activation.

There is no separate interface to learn once it's active. Verdicts, risk scores, and IOCs appear directly in the MetaDefender Cloud dashboard customers already use to submit and review files.

Adding Context to Sandbox Detection

MetaDefender Cloud's sandbox has always been capable of catching what static tools miss. MetaDefender Aether brings additional context: knowing if the file connects to something already seen, knowing how much confidence to place in the detection, and knowing what family or campaign it belongs to.

Explore zero-day detection in MetaDefender Cloud. Create a free Community account at metadefender.com to scan files and see reputation and sandbox analysis in action.

For full access to MetaDefender Aether's five-layer detection pipeline, talk to sales.

Zusätzliche Ressourcen

FAQ: MetaDefender Aether Integration with MetaDefender Cloud

What is MetaDefender™ Aether?

MetaDefender™ Aether is OPSWAT's AI-powered malware detection and sandboxing solution that combines Threat Reputation, Predictive AI, Adaptive Sandbox, Threat Scoring, and ML-powered Threat Hunting into a single verdict. It's designed to catch known, unknown, evasive, and zero-day file-based threats.

How does MetaDefender™ Aether improve MetaDefender™ Cloud sandboxing?

MetaDefender™ Aether adds reputation context, pre-execution prediction, risk scoring, and campaign-level attribution around every sandbox detonation. Instead of five separate reports to piece together manually, analysts get one consolidated, risk-scored verdict with MITRE ATT&CK mappings and extracted malware configurations.

What are the five detection layers?

The pipeline consists of Threat Reputation (checks against known indicators), Static Analysis (pre-execution AI prediction), Dynamic Analysis (sandbox emulation of evasive code), Threat Scoring (combines all evidence into one confidence score), and Threat Hunting (links samples to known malware families and campaigns). Each layer adds a different type of evidence to the final verdict.

Does MetaDefender™ Aether integrate with existing APIs, SIEM, and SOAR workflows?

Yes. It supports MetaDefender Cloud's public APIs, external REST APIs for file/URL/IP/domain submissions, SIEM and logging integrations, CI/CD tooling, and SOAR platforms for automated response, all within the existing dashboard.

Is MetaDefender™ Aether available on Free and/or Community tiers?

A free Community account provides basic file scanning with reputation and sandbox analysis. Full access to the complete five-layer pipeline requires package activation through an OPSWAT sales representative.

Bleiben Sie auf dem Laufenden mit OPSWAT!

Melden Sie sich noch heute an, um die neuesten Unternehmensinformationen zu erhalten, Geschichten, Veranstaltungshinweise und mehr.