Zero-Day Detection
for MetaDefender Core
OPSWAT’s AI-driven, on-premises zero-day detection solution for offline and regulated environments. It uses an emulation-based adaptive sandbox and AI-powered malware analysis to expose evasive threats, extract actionable IOCs, and support secure file inspection within MetaDefender Core workflows.
- Install in Minutes
- No Extra Integration Needed
- Uses Your Existing Policies
Unified Zero-Day Detection

Layer 1: Threat Reputation
Expose Known
Threats Fast
Stop known threats before deeper analysis.
Checks files, URLs, IPs, and domains against continuously updated reputation intelligence, online or offline.
Blocks reused malware and attacker infrastructure, forcing adversaries to rotate indicators and rebuild delivery paths.

Layer 2: Static Analysis
Predict Unknown Threats Before Execution
Close the Pre-Execution detection gap.
Predictive Alin AI analyzes file structure and behavioral features to predict malicious intent in milliseconds, without signatures or detonation.
Detects never-before-seen and polymorphic malware before it runs, reducing downstream sandbox demand while keeping file flows fast.

Layer 3: Dynamic Analysis
Force Hidden Threats to Reveal Themselves
Expose evasive malware that static and VM-based tools miss.
An emulation-based Adaptive Sandbox triggers malicious behavior and explores alternate execution paths without relying on a detectable virtual machine.
Reveals loader chains, runtime artifacts, obfuscated scripts, multi-stage payloads, and evasion techniques.

Layer 4: Threat Scoring
Prioritize What Matters Most
Turn complex threat behavior into an actionable verdict.
Correlates reputation, static, and dynamic analysis signals to assign a confidence-based risk score.
Highlights the highest-risk threats in real time, reducing false positives, alert noise, and analyst triage time.

Layer 5: Threat Hunting
Connect Threats to Campaigns
Move from isolated file detection to campaign-level intelligence.
ML-powered similarity search and Threat Pattern Correlation connect unknown samples to known malware, infrastructure, tactics, and related variants.
Uncovers malware families and attacker campaigns, forcing adversaries to overhaul their tools, infrastructure, and tradecraft.

Get Started in 3 Simple Steps
Activate Your Integration
Add your API key to enable the Adaptive Sandbox with built-In Threat Intelligence.
Configure Policies
Select which file types or risk categories will be automatically sent for dynamic analysis.
View Results
View sandbox verdicts, threat scores, & IOCs directly within your Core dashboard.
- Step 1
- Step 2
- Step 3
Product Overview
Learn how MetaDefender Aether detects zero-day threats at the perimeter by combining adaptive sandboxing, threat intelligence, threat scoring, and similarity search before files enter critical environments.
Embedded & Remote
Adaptive Sandbox Engine Features
The following table outlines Adaptive Sandbox remote and embedded engine feature set. It doesn’t include platform features, such as the API coverage, configurable ACL (Access Control List), OAuth integration, CEF (Common Event Format) syslog feedback, etc.
Please contact us to book a technical presentation and get a run-through of all platform features and capabilities.
Support Compliance
with Regulatory Requirements
As cyberattacks and the threat actors that carry them out become more sophisticated, governing bodies around the world are
implementing regulations to ensure critical infrastructure is doing what’s necessary to stay secure.
Recommended Resources
The Invariants of Cybersecurity
MetaDefender Aether for Core
SANS Detection & Response Survey
2025 OPSWAT Threat Landscape Report
Scan What Matters: 99.9% Precision AI Engine Improves Your Security Stack
Security-First MFT: AI-Native & Emulation-Driven Defense Against File-Based Attacks
Energy Provider Eliminates Alert Floods and Improves Zero-Day Detection with OPSWAT
0 results. Please try again.
FAQs
It's the embedded sandbox module inside MetaDefender Core-ideal when you want zero-day analysis tightly coupled to your existing Core pipelines (ICAP, kiosks, email, MFT), especially in regulated or air-gapped sites. Choose Aether if you want the full standalone analysis UI and broader TI workflows.
Use Core policy/CDR triggers (macros, scripts, embedded objects, active content) to auto-route just the risky 2-3% for emulation-maintaining throughput without missing stealthy stage-one vectors. This can also be used manually to analyze the behavior of a file.
Independent detection-logic updates (faster coverage), offline certificate validation for air-gapped ops, expanded filetype/installer coverage, and double-Base64 decoding so you keep pace with evasions without full upgrades.
Yes-Linux server (RHEL/Rocky) on-prem, no outbound dependency in offline mode, minimal egress options, and simple REST connection to existing Core. Designed for OT/ICS and classified networks.
Sharper triage (fewer escalations), faster root cause (decoded scripts/unpacked loaders), and ready-to-action IOCs that enrich your SIEM rules and playbooks.











