Layer 4 - Threat Scoring

Prioritize What Matters Most

Layer 4 turns evidence from across the Aether detection pipeline into an actionable, confidence-based risk verdict.

By the time a file reaches Threat Scoring, Aether may already know its reputation, have a Pre-Execution prediction from Predictive Alin AI, and have detailed runtime evidence from Adaptive Sandbox.

Threat Scoring brings those signals together.

Instead of forcing analysts to interpret reputation lookups, machine-learning predictions, behavioral indicators, and sandbox results independently, Layer 4 correlates the evidence to determine how strongly the file demonstrates malicious intent and how urgently it should be handled.

The result is clearer prioritization, less alert noise, and faster security decisions.

At a Glance

  • Purpose: Turn multi-layer evidence into an actionable risk verdict

  • Inputs: Threat Reputation, Predictive Alin AI, and Adaptive Sandbox findings

  • Evaluates: File structure, runtime behavior, malicious techniques, and threat context

  • Output: Confidence-based risk scoring and verdict

  • Best for: SOC triage, automated policy enforcement, and high-volume file security

  • Pipeline role: Convert detection evidence into a decision before Layer 5 Threat Hunting adds broader campaign context

Why Layer 4 Matters

Finding suspicious behavior is not the same as knowing how much it matters.

A file might contain an unusual script, contact an unfamiliar domain, use obfuscation, or exhibit one suspicious execution pattern. Any individual signal may be insufficient to make a confident decision.

Threat Scoring looks at the evidence together.

Aether correlates what was known before execution, what Predictive Alin AI identified from the file itself, and what Adaptive Sandbox observed during runtime.

This allows multiple weak or ambiguous signals to become meaningful when they appear as part of a broader malicious pattern.

Rather than giving analysts another list of findings to investigate, Layer 4 helps answer:

How much risk does the combined evidence actually represent?

What Threat Scoring Evaluates

Threat Scoring considers evidence across file structure, execution behavior, and threat intelligence, including:

  • Malicious execution flows

  • Loader and injection patterns

  • Script obfuscation

  • Persistence techniques

  • Command-and-control behavior

  • Malware family characteristics

  • Behavioral threat indicators

  • MITRE ATT&CK mappings

  • Malware Behavior Catalog mappings

  • Relationships between static file structure and observed runtime behavior

The value comes from correlation. A single suspicious characteristic may not determine the verdict, but several related indicators can expose malicious intent with much greater confidence.

How Layer 4 Fits Into the Aether Pipeline

Each Aether layer answers a different question.

Layer 1: Threat Reputation
Do we already know this threat?

Layer 2: Static Analysis
Does Predictive Alin AI detect signs of malicious intent Pre-Execution?

Layer 3: Dynamic Analysis
What does the file actually do when its behavior is exposed?

Layer 4: Threat Scoring
What does all of that evidence mean, and how risky is the file?

Layer 5: Threat Hunting
What other malware, infrastructure, variants, or campaigns is the threat connected to?

Layer 4 is the point where detection evidence becomes a security decision.

From Signals to a Consolidated Verdict

Security teams often have no shortage of detection data. The harder problem is deciding which signals justify action.

Threat Scoring reduces that burden by correlating evidence across Aether rather than treating each detection technology as an independent source of truth.

This helps security teams:

  • Prioritize the highest-risk files first

  • Reduce time spent investigating low-value signals

  • Reduce false positives and alert noise

  • Apply more consistent allow, block, or quarantine decisions

  • Feed clearer verdicts into automated security workflows

  • Give analysts the supporting evidence behind the decision

For high-volume environments, this matters as much as detection efficacy. A security system that identifies suspicious activity but cannot distinguish urgency simply moves the bottleneck to the analyst.

Detect Malicious Intent Across Multiple Signals

Modern malware frequently changes superficial characteristics to avoid detection.

Attackers can modify hashes, repackage executables, alter scripts, or make small changes to a payload without fundamentally changing how the attack operates.

Threat Scoring makes those minor modifications less effective because it evaluates relationships across structure, behavior, and execution technique, rather than relying on a single indicator.

Repeated loader behavior, injection patterns, persistence mechanisms, C2 activity, and other malicious techniques can still contribute to a high-risk verdict even when individual file characteristics change.

How Layer 4 Raises the Cost for Attackers

Threat Scoring operates higher on the Pyramid of Pain, where detection begins to focus on attacker tools and TTPs rather than easily replaced indicators.

By correlating malicious behaviors, Layer 4:

  • Makes reused execution patterns easier to recognize

  • Exposes malicious intent across multiple weaker signals

  • Reduces the effectiveness of simple payload modifications

  • Forces attackers to change how their tools behave, not just how their files look

  • Makes evasion increasingly dependent on redesigning behavioral techniques and attack logic

Changing a hash is easy. Changing how an attack works is considerably harder.

The Role of Layer 4

Layers 1 through 3 generate evidence.

Layer 4 decides what that evidence means.

Threat Scoring converts reputation intelligence, Pre-Execution AI predictions, and observed runtime behavior into a confidence-based risk verdict that analysts and automated systems can act on.

That gives Aether a critical capability beyond simply finding suspicious activity:

It helps security teams know what actually deserves their attention.