MetaDefender Aether by OPSWAT is a malware analysis sandbox for the dynamic analysis of files, URLs, and scripts to detect known, unknown, and zero-day threats. The system detonates potential payloads in a controlled environment using CPU-level emulation, a process designed to bypass common anti-analysis and anti-virtual machine evasion techniques. Its analysis pipeline combines static and dynamic methods, including Adaptive Threat Analysis (ATA), behavioral analytics, machine learning, and structural analysis for over 50 file types. This process incorporates executable decompilation, obfuscated VBA macro emulation, and script decoding to identify evasive malware, multi-stage attacks, and memory-only payloads.
Upon completion of an analysis, the platform generates Indicators of Compromise (IOCs), risk verdicts, and YARA rules, with findings mapped to the MITRE ATT&CK framework. The resulting threat intelligence can be used to retrain machine learning engines and validate the integrity of data backups. MetaDefender Aether supports integration with security infrastructure via REST APIs and SOAR platforms, and can function as an expansion to other MetaDefender products. The solution is available for on-premises, cloud, hybrid, and air-gapped deployments, with specific features for offline functionality in isolated networks.