https://catalogartifact.azureedge.net/publicartifacts/opswatinc1619007967290.opswat-mdcore-linux-013da399-6090-48a4-9cf4-efba04b964ae/image1_OPSWATlogosmallblue.png
OPSWAT MetaDefender Core Linux
av OPSWAT, Inc.
Just a moment, logging you in...
MetaDefender Core protects web applications and enterprise storage from malicious file content
MetaDefender Core provides a multi-layered approach to securing files by analyzing, detecting, and preventing file-borne threats before they cross the security perimeter. The platform combines advanced technologies including Predictive Alin AI, Metascan Multiscanning, Deep CDR, AI Content Inspection, Proactive DLP, Adaptive Sandbox, Threat Intelligence, File-based Vulnerability Assessment, SBOM, and Country of Origin.
Designed for critical infrastructure and sensitive workflows, MetaDefender Core enables organizations to trust no file by ensuring every file is safe, compliant, and operationally usable before access or transfer. It integrates seamlessly into existing infrastructure, securing uploads, downloads, email attachments, and file transfers without disrupting workflows
Predicts malicious file behavior and blocks threats pre-execution, without detonation
Using a machine-learning model trained on zero-day threats, Predictive Alin AI analyzes deep file structures and blocks risky files instantly, without detonation, emulation, or runtime analysis. Verdicts are delivered in milliseconds with a false positive rate near 0.1%.
Scans files with 30+ anti-malware engines
With 30+ leading anti-malware engines running in parallel, MetaScan™ Multiscanning combines signatures, heuristics, and machine learning to detect over 99.2% threats, improve malware visibility, and reduce false positives.
Disarms file-based threats and regenerates clean, usable files
Deep CDR™ strips embedded scripts, macros, QR codes, and other active content from 200+ file types, then regenerates clean, fully usable files in milliseconds, helping neutralize zero-day and evasive threats.
Detects AI-generated images, manipulated documents, and fraud indicators in files
AI Content Inspector flags AI-generated content, document manipulation, and fraud indicators from images, PDFs, and text-bearing files at ingest and returns policy-ready verdicts to catch the flagged files before approval.
Detects and enforces policies on sensitive content in files before transfer
Using pattern matching, custom rules, and AI-powered document classification, Proactive DLP™ detects and enforces policies (redact, remove, block) on PII, PHI, credit card numbers, access keys, adult images, and offensive text across 125+ file types.
Executes suspicious files in a controlled environment
Adaptive Sandbox emulates user-facing applications and extracts high-fidelity Indicators of Compromise (IoC) covering process behavior, system changes, dropped payloads, and network activity for faster triage and response.
Combines AI-driven sandboxing and global threat intelligence
Threat Intelligence analyzes file behavior, extracts sandbox-derived Indicators of Compromise (IoC) and applies similarity scoring to identify novel variants and campaign-level relationships at 99.6% detection accuracy.
Matches file hashes against a global database of known good and bad files
Reputation classifies files as known good, known bad, or unknown by comparing file hashes against a continuously updated database and advanced analyses such as metadata evaluation, content inspection, and contextual correlation.
Scans installers, libraries, and firmware before deployment.
File-Based Vulnerability Assessment analyzes installers, shared libraries, and firmware packages against a continuously updated database and produces detailed vulnerability reports with severity scoring and remediation guidance.
Inventories every component and dependency in an application.
Software Bill of Materials (SBOM) is a machine-readable inventory of open-source, third-party, and proprietary components inside applications and containers, correlating them against vulnerability databases and validate against EU CRA, NIS2, EO 14028, NIST requirements.
Identifies and enforces policies on files' geographic sources and vendors
Country of Origin (COO) uses static inspection, metadata, and digital signature analysis to determine the true origin and vendor of PE, MSI, and self-extracting files, then block or escalate files from high-risk regions and sources and allow trusted vendors to bypass unnecessary inspection.