Roughly 80% of the average SOC's operating budget goes to labor. An estimated $3.3 billion is spent annually in the U.S. alone on manual Tier-1 triage. And 42% of security alerts are never even opened, according to Command Zero.
Files add another source of friction. When a Command Zero investigation encounters a file, an analyst may need to stop the workflow, detonate the file separately, and add the results back into the case by hand. MetaDefender Aether™ returns a file verdict but incorporating that result into a documented incident still takes manual work.
MetaDefender Aether™, OPSWAT's zero-day detection solution, now connects directly to Command Zero's autonomous investigation platform, so the verdict and the case become a single record.

Key Takeaways
- If your SOC runs Command Zero, file investigations that used to require a manual detour now resolve inside the same case through the API your team uses
- If your SOC runs MetaDefender Aether, its verdicts now feed directly into a full, auditable investigation record instead of remaining in a separate tool
- The integration fits into existing workflows without requiring teams to replace existing tools or retrain analysts
- It works across cloud, hybrid, and air-gapped environments, extending the integration to critical infrastructure teams with different deployment requirements
- MetaDefender Aether reaches up to 99.5% detection efficacy and returns verdicts up to 40x faster than traditional sandboxes
- Early access is available now through OPSWAT account teams
If Your SOC Already Runs Command Zero
Command Zero already automates investigation tasks, such as translating questions into queries, correlating identity, endpoint, cloud, and SaaS data, and documenting each step. Files used to be an exception. File analysis previously required analysts to leave that workflow, run the file through a separate sandbox, and bring the results back into the case.
When Agent Zero encounters a file, whether from an email attachment, an endpoint alert, or a cloud storage event, it submits the sample to MetaDefender Aether automatically. The resulting analysis can include dropped files, registry changes, command-and-control callbacks, extracted indicators of compromise, and family attribution.
That information remains inside the Command Zero investigation workflow and becomes part of the case record. The integration works across cloud, hybrid, and fully air-gapped environments.

If Your SOC Already Runs MetaDefender Aether
MetaDefender Aether analyzes individual files and returns a consolidated verdict. Through Command Zero, that verdict can now become part of a broader investigation that includes identity, endpoint, cloud, and SaaS evidence.
The file analysis is documented alongside the rest of the investigation, and extracted indicators can support subsequent investigative pivots without requiring analysts to re-enter the findings manually. This gives teams a direct path from file analysis to a complete, auditable case record.

The State of the SOC
Attacker speed and alert volume explain why file analysis keeps becoming the bottleneck for teams on both sides of this integration. The numbers below come from Command Zero's "The 51-Second Problem" and "When Brute Force Still Works" articles.
SOC Speed and Alert Volume Benchmarks
Stat | Context |
51 seconds | Fastest recorded adversary breakout time (2024) |
30 min–4 hrs | Mean time to detect for top-performing SOC teams |
90+ minutes | Minimum realistic time from alert to coordinated response |
90% | SOCs reporting they're overwhelmed by alert backlogs |
80 billion | Credentials aggregated from stealer logs in 2025 |
600 million | Credentials released in a single day (2025) |
90% drop | Reduction in failed logins within 72 hours after one customer's remediation |
Closing that kind of context gap produces measurable results fast. This integration aims for the same shift, applied to files instead of credentials.
What This Looks Like in Practice
Command Zero's investigation logs show how the workflow changes when file analysis becomes part of the case. In one published phishing case, Agent Zero traced a covert inbox rule back to a stolen session token and anonymous proxy, running 42 questions across 219 records and reaching a verdict in 5 minutes and 9 seconds.
Command Zero's Phishing Analysis workflow already automates header analysis, URL detonation, and user behavior correlation. A malicious attachment can still route an analyst outside the workflow. The MetaDefender Aether integration keeps the file verdict inside the same case and on the same timeline.
One OPSWAT customer, a global financial institution, faced this bottleneck with nearly 1,000 suspicious emails a day queuing through a VM-based sandbox. During high-priority incidents, analysts had to pause automated jobs just to free up capacity. After moving detection to MetaDefender Aether, the queue was eliminated, and file analysis dropped from minutes to seconds.
Command Zero's insider threat use case provides another example. In the "last day engineer" scenario of the company’s insider threat use case, an employee resigns on a Friday, clones 14 proprietary Git repositories over the weekend, and uploads a customer database to a personal drive without triggering a DLP alert. Before Command Zero, that exfiltration surfaced three weeks later during an offboarding audit. With Command Zero's HR-triggered investigation, the evidence package was ready before the employee's last day.

Files, cloned repositories, uploaded databases, and exported archives can all provide evidence that complements behavioral correlation. A Gartner Peer Insights review from a government CISO describes the Command Zero experience as "fantastic" from early testing through the deployable product. Command Zero's own threat research documents a credential-stuffing investigation at a mid-sized financial services company.
The Technical Foundation
MetaDefender Aether's five-layer engine handles file analysis, while Command Zero automates the surrounding integration workflow.
MetaDefender Aether Capability Breakdown
Capability | What It Does | Key Stats |
Five-layer detection pipeline | Threat reputation, static analysis, dynamic analysis, threat scoring, and threat hunting working together | Up to 99.5% detection efficacy after Threat Hunting (internal benchmark testing) |
Predictive Alin AI (static analysis) | Returns a verdict before a file needs emulation | As little as 50 milliseconds on high-risk executables |
CPU-level emulation (dynamic analysis) | Forces malware to run its real logic instead of hiding from a VM | Up to 40x faster than traditional sandboxes |
Threat hunting / behavioral mapping | Maps findings to attacker tradecraft, not just disposable indicators | 900+ behavioral indicators aligned to MITRE ATT&CK |
ML similarity search | Connects a sample to related families, variants, and shared infrastructure | Surfaces related activity automatically, before it resurfaces elsewhere |
In a third-party evaluation, OPSWAT's Adaptive Sandbox detected 95% of AI-generated malware samples in Venak Security's 2026 sandbox test. Command Zero documents every question asked and every data source queried, allowing MetaDefender Aether's findings to become part of an auditable investigation record that teams can use with leadership, auditors, and regulators. That documented decision trail matters as SOCs adopt more autonomous tooling.
About Command Zero
Command Zero is an autonomous and AI-assisted SOC investigation platform built on a question-based method, where every step is visible, auditable, and reproducible. It ships with thousands of pre-built expert questions mapped to real SOC workflows and connects to existing tools without a data migration. Command Zero customers have completed more than 500,000 investigations and report up to a 90% reduction in Tier 1 escalations.
We aren't the first security vendor to integrate into Command Zero's investigation layer. ReversingLabs recently partnered with Command Zero to feed its threat intelligence corpus into the same workflows, cutting false positives and adding historical context on attack patterns. No matter which vendor supplied the evidence, it lands inside the case on which investigators are already working.
From Alert Fatigue to Answered Questions
Command Zero automates investigation tasks while MetaDefender Aether automates file analysis. For the 2,100+ organizations that use OPSWAT to protect their perimeter, the integration brings MetaDefender Aether into the investigation workflow. Command Zero customers gain zero-day file detection within any case that includes a file.
We're working closely with the Command Zero team to bring this integration to our joint customers. Chat with an expert about early access to the integration.
Frequently Asked Questions
What does the OPSWAT and Command Zero integration do?
It connects Command Zero's autonomous investigation platform directly to MetaDefender Aether, so when an investigation encounters a file, MetaDefender Aether returns an evidence-backed file verdict automatically, without an analyst pausing to run a manual sandbox detonation.
What is MetaDefender Aether?
MetaDefender Aether is OPSWAT's unified zero-day detection solution. It delivers a single, consolidated verdict per file through five coordinated layers: threat reputation, static analysis (Predictive Alin AI), dynamic analysis, threat scoring, and threat hunting.
How is MetaDefender Aether faster than a traditional sandbox?
Predictive Alin AI returns pre-execution verdicts on high-risk executables in as little as 50 milliseconds, letting high-confidence files skip emulation entirely. Files that still need deeper inspection go through CPU-level emulation, up to 40 times faster than traditional sandboxes.
Can this integration run in air-gapped environments?
Yes. MetaDefender Aether runs in cloud, hybrid, and fully air-gapped deployments, so operators who cannot send samples offsite can still use the integration within those deployment environments.
When is the integration available?
The integration is in active development. Teams can request early access through their OPSWAT account team.
