Title
Create new category
Edit page index title
Edit category
Edit link
Release Notes for v3.2.0
Date: 31st July 2026
Upgrading directly from versions prior to 2.5.1 to 3.2.0 is not possible!
Recommended Upgrade Path: First upgrade to 2.5.1, then install 3.2.0.
MetaDefender Aether™ 3.2.0 (including MetaDefender Sandbox™ capabilities)
What’s new
Predictive Alin AI — a new Layer 2 for static analysis: The headline of this release: Aether’s architecture gains a new second layer. Predictive Alin AI brings AI-driven predictive verdicts to static analysis, assessing files for malicious intent earlier in the pipeline — before emulation or sandbox detonation — for faster, smarter triage across the entire Aether stack.

Aether Processing Engine: Scan results now render as a numbered, sequential view of every layer that touched the file — reputation, static, dynamic, scoring, and threat hunting — with each layer's specific contribution shown inline. A new second static analysis layer, Predictive AI, appears alongside the multiscanning verdict, so you can see both the signature-based and the model-based determination for the same sample. The evidence-layer counter (e.g. 3/5) shows how many layers produced positive findings, independent of scan completion.

Actionable Threat Attribution: Stop guessing what you're dealing with. Sandbox now delivers stronger, clearer classification statements in place of ambiguous tags — giving analysts immediate, confident answers about a threat's identity and intent, cutting investigation time and increasing trust in every result. A more robust attribution model eliminates weak, hedged statements in favor of decisive, evidence-backed verdicts.

Implemented instrumented file system within the PE emulator: The PE emulator now instantiates an instrumented filesystem in which the emulated sample resides. A great step towards the first official version of Aether’s PE emulator. This feature enables proper emulation of any file operation and interaction which would have previously terminated the emulation. This feature brings the flexibility of manually configuring the fake files that "exist" within, so that the emulated sample actually locates any file defined in the configuration file. Hence, this milestone not only enables a new feature, but extends configuration and flexibility of the emulation environment.
Detection for Emerging Evasion Techniques: Threat actors keep getting more creative — Sandbox keeps pace. This release adds detection for etherhiding (concealing threat actor infrastructure inside blockchain transactions) and intentionally malformed .NET assemblies built to break automated analysis tools.

Smarter Remote Template Detection: Remote template injection analysis got a full pass this release, aimed at keeping the false-positive rate flat while closing real detection gaps. A rebuilt link-detection and URL-classification pipeline now tells genuine injection attempts apart from ordinary embedded links — fixing two indicators that had been flagging legitimate URLs as malicious, and closing a gap where obfuscated, octal-encoded malicious IP links were going undetected. Fewer false alarms, no loss of coverage.
Improvements
Extension and Migration of Syslog Functionality: The syslog configuration moved from the broker config file to the Admin Panel (the configuration is not automatically migrated, see details at CEF Syslog Feedback. The syslog functionality was extended to also log authentication events and admin setting changes along with the scan result summaries.
Broader Detection & Coverage Improvements: This release also expands detection coverage on several fronts: new detection engineering for wiper malware, CAPTCHA identification via OCR (including obfuscated but rendered fake CAPTCHAs used in ClickFix attacks), new config extractors for PrivateLoader and Quasar RAT, and expanded IOC coverage in the local reputation database.
See the "Technical Datasheet" for a complete list of features: https://docs.opswat.com/filescan/datasheet/technical-datasheet