MetaDefender Distributed Cluster v2.5.0 introduces major enhancements that help security and platform teams manage trusted file workflows with greater speed, automation, and control. The new version improves observability, streamlines updates, and strengthens integration across the MetaDefender ecosystem.
MetaDefender Distributed Cluster enables high volume, distributed file security operations across on-premises, cloud, and Kubernetes environments. These updates reduce manual work, accelerate investigations, and simplify large scale operations.
Operate with Confidence
Readiness Health Checks with /readyz
Cluster components can now be monitored using a /readyz endpoint. This feature supports Kubernetes readiness probes, load balancer checks, and automation systems. It follows the Kubernetes convention for health endpoints and complements MetaDefender Core™ readiness practices.
Webhook Callbacks with Callback URL Header
Instead of polling, you can receive scan results through a webhook. By setting a Callback URL header on API submissions, the cluster will send results directly when analysis completes. This reduces latency and system load while supporting event-driven workflows.
Accelerate Investigations
Export Scan Results in JSON
Per-file scan results can now be exported in JSON format. This simplifies integration with SOAR platforms, custom analytics, and long-term evidence storage. The format aligns with MetaDefender Core REST responses for consistent automation.

Export Processing History to STIX or CSV
Auditors and threat intel teams can now export Processing History as STIX (for intel exchange) or CSV (for spreadsheets/SIEM import). CSV export is a common pattern across OPSWAT products for auditability; STIX adds interoperability with threat intel platforms and cases where IOC sharing is required.
Simplify Lifecycle Management
Remove Abandoned Module Packages
You can now identify and delete unused or outdated module packages. This keeps deployments lean, current, and compliant while reducing storage use and confusion during updates.

Local Folder Engine Updates from Control Center
Environments without internet access can place update packages in a local directory. Control Center will detect and distribute them to MetaDefender Distributed Cluster Workers automatically. This enables secure updates in air-gapped or restricted networks with consistent provenance and audit tracking.
Unify File Security Operations
Integration with MetaDefender Storage Security™ and MetaDefender Kiosk™
Distributed Cluster now integrates fully with MetaDefender Storage Security and MetaDefender Kiosk.
- Storage Security: Centralize Core workers and route scanning at scale for S3, Azure, NetApp, SMB, and NFS.
- Kiosk: Enforce secure media workflows at entry points while scaling Core capacity at the backend.
How This Release Helps Your Team
- Platform and SRE Teams: Kubernetes-ready health checks, webhook callbacks, and local folder updates simplify deployment and reduce manual work.
- Security and Incident Response Teams: JSON, STIX, and CSV exports enable faster investigations, evidence collection, and compliance reporting.
- Architecture and Operations Teams: Unified integrations with Storage Security and Kiosk simplify management across hybrid and air-gapped environments.
Next Steps
Ready to get started with MetaDefender Distributed Cluster v2.5.0? Check out these helpful resources:
- Visit opswat.com/products/metadefender/distributed-cluster
- Upgrade to MetaDefender Distributed Cluster 2.5.0
- Access release note for full technical details
For questions or support, contact support@opswat.com
