MetaDefender Sandbox is a dynamic malware analysis and threat detection solution from OPSWAT that detonates files and URLs in a controlled environment. It utilizes adaptive threat analysis technology and a Rapid Dynamic Analysis engine to analyze, record, and classify file behavior, identifying threats such as zero-day malware and targeted attacks. The system is designed to bypass anti-analysis techniques like geofencing by executing files across multiple operating systems and emulating targeted applications, including Microsoft Office and PDF readers.
The analysis process focuses on extracting Indicators of Compromise (IOCs) and classifying file behavior for automated interpretation. It can emulate highly obfuscated macro malware and scripts to expose malicious behavior. For integration and operational management, the platform includes a comprehensive API for programmatic access, along with configuration and administration capabilities.