MetaDefender Core by OPSWAT is a threat prevention and file analysis platform designed to process digital content like files, archives, and source code to protect IT and OT infrastructures. It utilizes a customizable workflow engine to apply a combination of security technologies. Its primary capabilities include multi-scanning with over 30 anti-malware engines, Deep Content Disarm and Reconstruction (Deep CDR) for file sanitization across over 170 file types, file-based vulnerability assessment, Proactive Data Loss Prevention (DLP), and dynamic analysis using an adaptive sandbox for zero-day threat detection. The platform also performs file type verification and deep archive extraction to analyze nested objects.
The system is engineered for deployment across on-premises, cloud, containerized (Docker, Kubernetes), and air-gapped environments on Windows and Linux operating systems. Its architecture supports high-throughput processing through scalable, multi-node configurations with load balancing and high availability. Integration with existing security products and applications is facilitated through a REST API, ICAP server, and Webhook interfaces. A central console allows for the configuration of security policies, and system data can be exported to SIEM solutions via syslog for monitoring and analysis.