MD Core Engine Features

OPSWAT Filescan's Sandbox technology is available as part of an integration with MD Core. The integration is available with two different engine types: embedded and remote sandbox engine (with full reporting). The embedded engine is deployed with MD Core, similar to other engines (CDR/DLP). The remote engine requires a side-by-side installation of the full OPSWAT Filescan (Sandbox) platform.

FeatureEmbedded EngineRemote Engine
Installation OSWindows, LinuxUbuntu (Linux)
File parsersYesYes
File certificate validationYesYes
Image text analysis (OCR)YesYes
Microsoft Office file emulationYesYes
Powershell script emulationNoYes
URL emulation (ML based phishing detection)NoYes
Fuzzy hash lookupYesYes
Google safe browsingYesYes
OPSWAT reputation lookupYesYes
YARA pattern matchingYesYes

Note: for a full list of engine features of the OPSWAT Filescan (Sandbox) standalone product, then visit here.

Type to search, ESC to discard
Type to search, ESC to discard
Type to search, ESC to discard