MetaDefender Core is an advanced threat detection and prevention platform that proactively analyzes, detects and neutralizes file-borne threats before they can breach your security perimeter.
Note: This is a contract listing for use with a private offer only. This listing is not meant to be transacted outside of an AWS private offer. To inquire about a Private Offer, please contact us at apn-sales@opswat.com.
MetaDefender Core provides a multi-layered approach to securing files by analyzing, detecting, and preventing file-borne threats before they cross the security perimeter. The platform combines advanced technologies including Predictive Alin AI, Metascan Multiscanning, Deep CDR, AI Content Inspection, Proactive DLP, Adaptive Sandbox, Threat Intelligence, File-based Vulnerability Assessment, SBOM, and Country of Origin.
Designed for critical infrastructure and sensitive workflows, MetaDefender Core enables organizations to trust no file by ensuring every file is safe, compliant, and operationally usable before access or transfer. It integrates seamlessly into existing infrastructure, securing uploads, downloads, email attachments, and file transfers without disrupting workflows
Predicts malicious file behavior and blocks threats pre-execution, without detonation
Using a machine-learning model trained on zero-day threats, Predictive Alin AI analyzes deep file structures and blocks risky files instantly, without detonation, emulation, or runtime analysis. Verdicts are delivered in milliseconds with a false positive rate near 0.1%.
Scans files with 30+ anti-malware engines
With 30+ leading anti-malware engines running in parallel, MetaScan™ Multiscanning combines signatures, heuristics, and machine learning to detect over 99.2% threats, improve malware visibility, and reduce false positives.
Disarms file-based threats and regenerates clean, usable files
Deep CDR™ strips embedded scripts, macros, QR codes, and other active content from 200+ file types, then regenerates clean, fully usable files in milliseconds, helping neutralize zero-day and evasive threats.
Detects AI-generated images, manipulated documents, and fraud indicators in files
AI Content Inspector flags AI-generated content, document manipulation, and fraud indicators from images, PDFs, and text-bearing files at ingest and returns policy-ready verdicts to catch the flagged files before approval.
Detects and enforces policies on sensitive content in files before transfer
Using pattern matching, custom rules, and AI-powered document classification, Proactive DLP™ detects and enforces policies (redact, remove, block) on PII, PHI, credit card numbers, access keys, adult images, and offensive text across 125+ file types.
Executes suspicious files in a controlled environment
Adaptive Sandbox emulates user-facing applications and extracts high-fidelity Indicators of Compromise (IoC) covering process behavior, system changes, dropped payloads, and network activity for faster triage and response.
Combines AI-driven sandboxing and global threat intelligence
Threat Intelligence analyzes file behavior, extracts sandbox-derived Indicators of Compromise (IoC) and applies similarity scoring to identify novel variants and campaign-level relationships at 99.6% detection accuracy.
Matches file hashes against a global database of known good and bad files
Reputation classifies files as known good, known bad, or unknown by comparing file hashes against a continuously updated database and advanced analyses such as metadata evaluation, content inspection, and contextual correlation.
Scans installers, libraries, and firmware before deployment.
File-Based Vulnerability Assessment analyzes installers, shared libraries, and firmware packages against a continuously updated database and produces detailed vulnerability reports with severity scoring and remediation guidance.
Inventories every component and dependency in an application.
Software Bill of Materials (SBOM) is a machine-readable inventory of open-source, third-party, and proprietary components inside applications and containers, correlating them against vulnerability databases and validate against EU CRA, NIS2, EO 14028, NIST requirements.
Identifies and enforces policies on files' geographic sources and vendors
Country of Origin (COO) uses static inspection, metadata, and digital signature analysis to determine the true origin and vendor of PE, MSI, and self-extracting files, then block or escalate files from high-risk regions and sources and allow trusted vendors to bypass unnecessary inspection.
Highlights
Quickly scan all files with top 30+ antivirus engines and detect over 99% of known malware.
Recursively sanitize 100+ file types with market-leading Deep CDR technology to remove all potential embedded threats.
Reliable, scalable solution to meet the needs of both small customers and large or complex enterprises.
Access real-time vendor security and compliance information through their Trust Center powered by Drata or Vanta. Review certifications and security standards before purchase.
AWS Marketplace now accepts line of credit payments through the PNC Vendor Finance program. This program is available to select AWS customers in the US, excluding NV, NC, ND, TN, & VT.
Pricing is based on the duration and terms of your contract with the vendor. This entitles you to a specified quantity of use for the contract duration. If you choose not to renew or replace your contract before it ends, access to these entitlements will expire.
Additional AWS infrastructure costs may apply. Use the AWS Pricing Calculator to estimate your infrastructure costs.
This listing has one pricing dimension: an annual subscription for MetaDefender Core Windows, billed by units. You commit to a 12-month term and choose the unit quantity that fits your needs. There are no separate tiers or instance sizes on the Marketplace. Pricing scales with the number of units you buy, so you add units as your file-processing volume grows. The product deploys on Windows servers and processes files for threat detection, sanitization, and vulnerability assessment. You pay one annual fee based on the unit count you select.
Top-of-mind questions for buyers
What does one unit of MetaDefender Core Windows represent for billing?
The Marketplace lists pricing by units for the annual subscription. The dimension and crawled content do not define what a single unit maps to, such as a server, engine package, or file-processing capacity. Contact the vendor to confirm how units are counted for your deployment before you commit.
How does the annual subscription bill compared to usage-based options?
You commit to a 12-month term and pay one annual fee based on the unit quantity you select. Charges do not meter by hours run or files scanned. The fee stays flat for the term regardless of processing volume. This model suits steady, ongoing file-scanning workloads on Windows servers.
What happens if my file-processing volume grows during the annual term?
Pricing scales with the number of units you buy. If your volume outgrows your current unit count, you add more units rather than moving to a different tier. There are no separate instance sizes on the Marketplace. Contact the vendor to confirm how added units apply mid-term.
Tell us how we can improve this page, or report an issue with this product.
Give us feedbackReport a problem with this product or seller
Legal
Vendor terms and conditions
Upon subscribing to this product, you must acknowledge and agree to the terms and conditions outlined in the vendor's End User License Agreement (EULA).
Content disclaimer
Vendors are responsible for their product descriptions and other product content. AWS does not warrant that vendors' product descriptions or other product content are accurate, complete, reliable, current, or error-free.
An AMI is a virtual image that provides the information required to launch an instance. Amazon EC2 (Elastic Compute Cloud) instances are virtual servers on which you can run your applications and workloads, offering varying combinations of CPU, memory, storage, and networking resources. You can launch as many instances from as many different AMIs as you need.
To access the MetaDefender Core web-based management console for the first time, connect to the IP address of the instance using a browser (e.g. http://localhost:8008). You will then be guided through the setup wizard to configure, license and use the product.
Connecting to MetaDefender Core AMI Instance console:
To connect to your MetaDefender Core command-line console, you will need to use RDP. For further information about the standard AWS method of connecting to an instance, see information described here: Connect to your Windows instance - Amazon Elastic Compute Cloud
AWS Support is a one-on-one, fast-response support channel that is staffed 24x7x365 with experienced and technical support engineers. The service helps customers of all sizes and technical abilities to successfully utilize the products and features provided by Amazon Web Services.
Scans files using 30+ antivirus engines to detect over 99% of known malware threats.
Content Disarm and Reconstruction
Recursively sanitizes 100+ file types using Deep CDR technology to remove embedded threats.
Vulnerability Scanning and Reporting
Performs vulnerability scanning and reporting on installers, binaries, and applications.
Multiple Deployment Options
Supports flexible deployment via NVME, containers, and Amazon EKS with REST API integration and ICAP protocol support.
Zero-Day Attack Protection
Provides protection against zero-day attacks and data breaches through multi-layer security architecture.
Multi-Storage Platform Support
Malware scanning across Amazon S3, Amazon EBS, Amazon EFS, and Amazon FSx for object, block, and file storage environments.
Multiple Scanning Engines
Support for Sophos, CSS Premium, and CSS Secure engines that can be used individually or simultaneously to optimize detection accuracy and performance.
Flexible Scanning Models
Event-based scanning on upload, retroactive scanning on-demand or scheduled, and API-based scanning before write operations for migrations and application workflows.
In-Tenant Deployment Architecture
Installation and operation within customer AWS accounts with data remaining in the specified region, supporting private VPC endpoints and linked account management.
Automated Response and Remediation
Automated quarantine, tagging, and deletion of detected malware with integration to downstream workflows, alerts, and enforcement policies through object tagging.
Intrusion Detection and Prevention
Host-based intrusion detection and prevention (IDS/IPS) capabilities to defend against network threats and zero-day exploits
Application Control
Application control functionality to lock down servers and secure Docker containers with DevOps-friendly API security processes
Malware Protection
Anti-malware protection with behavioral analysis and predictive machine learning for Windows and Linux workloads
Integrity Monitoring
File and System Integrity Monitoring to streamline compliance and audit evidence gathering
Vulnerability Exploitation Prevention
Vulnerability exploit shielding to prevent exploitation of unpatched systems without requiring live system patching
File sanitization has transformed zero-trust workflows and now protects every inbound channel
Reviewed on Aug 01, 2026
Review from a verified AWS customer
What is our primary use case?
My primary use case for MetaDefender is securing the file instruction channels including web portal uploads, email attachments, and removable media transfers. I use its deep content disarm and reconstruction, that is CDR, and multi-scanning capabilities to sanitize incoming files and prevent zero-day malware and file-born threats from entering my internal network.
A primary example in my environment involves securing vendor and contractor access via removable media. Whenever third-party engineers or external staff bring a USB device containing firmware updates, logs, or diagnostic tools into my secure facility, they cannot plug them directly into any endpoint. Instead, they must plug the USB into an isolated MetaDefender Kiosk station at the entrance. The Kiosk scans the entire flash drive using MetaDefender Multi-scanning technology with over 20 antivirus engines simultaneously to detect known malware. Right after that, it applies the deep CDR, that is, content disarm and reconstruction, which strips out active macros, embedded scripts, or dynamic content from files such as PDFs, Word documents, or installation packages. Once the scan finishes clearly, the files are copied to an encrypted, sanitized USB drive or securely pushed to my MetaDefender vault. This ensures zero-day threats or hidden malicious payloads on USBs never reach my internal network.
MetaDefender acts as my automated gateway for zero-trust file processing. It integrates directly with my API and ICAP workflows so that every incoming document is scanned, sanitized with deep CDR, and passed through to end-users or internal storage without manual intervention from my security team. It seamlessly automates file security without slowing down day-to-day operations.
What is most valuable?
In my opinion, the best features MetaDefender offers are Deep CDR and Multi-scanning. Multi-scanning runs files across 20+ AV engines simultaneously to catch hidden malware that a single engine might miss, while Deep CDR sanitizes files by stripping active macros and scripts, returning clean, usable documents without breaking their formatting.
Deep CDR has made the biggest difference for my team, and it has significantly reduced alert fatigue and saved my SOC team hours of manual investigation. Instead of constantly analyzing isolated file alerts or quarantining false positives, MetaDefender automatically sanitizes incoming files at the perimeter, allowing my team to focus on proactive threat hunting and high-priority security incidents.
The centralized reporting and granular workflow policies are also major highlights. Being able to customize rules based on specific file extensions, sources, or user groups gives me total control over the data handling. The proactive DLP feature also helps prevent sensitive data leakage alongside threat neutralization, making it a very well-rounded package.
MetaDefender has positively impacted my organization by vastly improving my security posture by eliminating file-born zero-day threats before they hit my core network. Beyond threat prevention, it has streamlined business operations. Employees and external partners can share files with complete confidence, knowing that incoming content is automatically sanitized without causing delays or breaking business workflows.
Since implementing MetaDefender, I have seen a 90% reduction in file-related security incidents and false positives reaching my analysts. I have also cut down the file processing dwell time significantly. Most inbound documents are sanitized and delivered in under five seconds. On top of that, it has freed up roughly 10 to 15 hours per week for my SOC team that was previously spent manually investigating quarantined file alerts.
What needs improvement?
The administrative UI could be modernized and made more intuitive, as managing deep custom workflows across complex file types has a bit of a learning curve. Additionally, executive-level reporting could be improved out of the box. Right now, generating high-level executive summaries often requires manual exporting or custom API scripts. Simplifying license management when updating or swapping individual AV engines with the multi-scan package would also be a big help.
On the technical support side, while standard ticket resolution is prompt, getting complex escalations or custom integration assistance up to senior engineers can sometimes take a couple of days. Regarding integration, while the REST APIs and ICAP connectors work reliably, the developer documentation could be expanded with more out-of-the-box code examples for custom internal applications to speed up deployment.
For how long have I used the solution?
I have been using MetaDefender for one and a half years.
What other advice do I have?
MetaDefender's approach to AI governance and security is solid, particularly with its MetaDefender IT or OT Security for LLMs and AI-driven threat analysis. It effectively prevents data leakage by sanitizing sensitive prompts and file uploads before they reach Gen AI models. Its governance policies ensure strict compliance, zero-trust controls, and auditing, making sure AI adoption does not introduce unmonitored shadow AI or sensitive data exposure in my environment.
The accuracy and reliability of MetaDefender's AI features are very high. Because its threat analysis combines heuristic AI models with multi-engine detection, false positives are extremely low. When it comes to Deep CDR and document sanitization, it reliably strips out malicious components while maintaining file integrity and formatting, meaning end-users get dependable, functional files without false alarms.
I have MetaDefender deployed in a hybrid cloud environment. I run MetaDefender Core on-premises within my core data center to maintain strict zero-trust controls and handle local file processing, while utilizing AWS cloud infrastructure to scale file scanning for my web applications and external cloud storage connections. This hybrid setup gives me both low latency for local systems and high availability for cloud workloads.
I primarily use AWS, that is, Amazon Web Services, for my cloud infrastructure. I host my MetaDefender Core instance on EC2 within AWS to handle high-volume file scanning for my web applications and cloud storage buckets seamlessly.
I procured MetaDefender through the AWS Marketplace. It simplifies my billing process by consolidating the licensing under my existing AWS enterprise agreement, while also allowing me to deploy and scale instances across my cloud infrastructure very quickly.
My main advice is to clearly define your file workflow policies before deployment. Take full advantage of the Deep CDR capabilities rather than relying solely on traditional antivirus scanning, as sanitized files offer much better protection against zero-day threats. Additionally, plan your integration carefully around your main data injection points, such as web portals or email gateways, and run through a proof of concept to customize rules for your specific file types.
Overall, MetaDefender is a robust, essential piece of my security stack that significantly reduces my attack surface for file-based threats. While there is some minor room for growth in the user interface, reporting, and developer documentation, its core capabilities such as Deep CDR and Multi-scanning make it well worth the investment for any enterprises looking to enforce zero-trust file security. I rate this product a 9 out of 10.
Which deployment model are you using for this solution?
Hybrid Cloud
If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?
Amazon Web Services (AWS)
Rajkumar Gupta
Adaptive policies have reduced downtime and simplified secure protection for cloud-based VMs
Reviewed on Jul 22, 2026
Review from a verified AWS customer
What is our primary use case?
My main use case for MetaDefender is on my devices. I have a specific example of how I use MetaDefender on my devices in that it has been installed by the administrator on my VMs which are being listed on my public cloud.
I don't have anything specific to add about how I use MetaDefender in my setup, as it is protecting my whole VMs, so not any particular file.
What is most valuable?
The best features MetaDefender offers, in my opinion, are that it adapts the policies on the go, and that is the best feature.
When I say it adapts policies on the go, it has the ability that if there is a new policy or the new configuration that has come up without any downtime, it just adjusts it and reiterates to all of the users and all of the devices. MetaDefender has positively impacted my organization as it has reduced time for the users.
MetaDefender reduces time for users in their working, as it does not occupy the RAM usage of their devices plus it does not take time for the downtime or shutting down or the rebooting of the devices.
What needs improvement?
I have not seen any areas where I can suggest improvements for MetaDefender, so probably it is good enough. I would rate it an eight because its interface can be improved and it can improve their integrations as well, so there is room for improvement.
For how long have I used the solution?
I have been working in my current field for four and a half years. I have been using MetaDefender for the past six months.
What do I think about the stability of the solution?
MetaDefender is stable.
What do I think about the scalability of the solution?
MetaDefender's scalability is pretty much scalable.
How are customer service and support?
The customer support is good.
Which solution did I use previously and why did I switch?
I previously used a different solution, Palo Alto, which I switched from because it was very expensive.
What was our ROI?
I have seen a return on investment as fewer employees are needed in terms of implementation.
What's my experience with pricing, setup cost, and licensing?
My experience with pricing, setup cost, and licensing is that it is good and at par with other competitors.
Which other solutions did I evaluate?
Before choosing MetaDefender, I evaluated other options, including Palo Alto and Check Point, as many were evaluated.
What other advice do I have?
My impression of the detection rates provided by MetaScan Multi-scanning is that it is good and pretty accurate. I would assess the effectiveness of Deep CDR in reconstructing files safely and without signatures as they are pretty much effective, and it is really useful for the administrator.
My thoughts on the file-based vulnerability assessment feature in identifying vulnerabilities before deployment are that it is good, and it is a very good feature. I use adaptive sandbox analysis, and its impact on analyzing suspicious files is very great because it detects pretty much early.
I am using the enhanced reporting and audit visibility features, and they have helped meet our audit requirements as it has given us a great requirement study and plus it has also helped in ISO audit requirement as well. I would assess the effectiveness of the solution in blocking or sanitizing content based on policy as good and pretty much effective.
My advice to others looking into using MetaDefender is that if you are looking ahead at a solution which can be implemented quickly and at a lesser cost, go ahead with it. I would rate this product an eight overall.
DineshKumar31
Security workflows have improved as it identifies threats and streamlines vulnerability patching
Reviewed on Jul 06, 2026
Review provided by PeerSpot
What is our primary use case?
The major use cases of MetaDefender in my work environment involve preventing malware updates, data breaches, and compliance violations through scanning files for malware, vulnerabilities, and sensitive data at the network perimeter.
What is most valuable?
The best features of MetaDefender include its ability to detect malware and vulnerabilities, which I also use at server levels, including production and testing servers, helping me identify and address vulnerabilities by applying patch updates.
When sanitizing files based on policies, MetaDefender processes and sanitizes files to remove hidden content, including embedded objects and scripts while preserving the visible content.
I use MetaDefender Archive Extractor, which supports over 30 archive file types, improving detection and preventing archive bombs, allowing administrators to perform archive handling once for each file type.
What needs improvement?
I would like to see improvements in the tool's automation capabilities. It would be beneficial if it could automatically create tickets and notify responsible teams about any identified vulnerabilities rather than relying on a manual process.
I want to see enhancements allowing for automatic ticket creation using APIs to streamline the workflow and assign tickets to respective teams.
For how long have I used the solution?
I have been using MetaDefender for the last two years on my official laptop.
What do I think about the stability of the solution?
I do not have any stability issues with MetaDefender.
What do I think about the scalability of the solution?
MetaDefender is scalable; it allows for automation in scaling resources as needed during peak times.
How are customer service and support?
I would rate technical support as a nine out of ten.
Which solution did I use previously and why did I switch?
I have evaluated other options available in the market, such as Microsoft and McAfee, but found MetaDefender to be distinct.
I decided to go with MetaDefender due to its architectural compatibility with the client's budget requirements, as its scanning and vulnerability detection capabilities are better than other tools.
How was the initial setup?
For me, onboarding MetaDefender was not too difficult, being balanced between straightforward and complex.
What was our ROI?
I have seen measurable benefits, as MetaDefender saves time, preventing the need for manual processes associated with other tools.
What other advice do I have?
The detection rates from MetaScan multi-scanning are managed mainly by other teams in alignment with our organization policy, where they can achieve detection rates of 81-87% with four engines or 95% with sixteen engines, and the comparison with Microsoft Defender often yields similar results.
I do not have an opinion on the effectiveness of Deep CDR in file reconstruction.
We have a process in place for identifying vulnerabilities before deployment where team members raise tickets on the ServiceNow portal for the respective teams to address.
I do not use Adaptive Sandbox analysis, as that is managed by another team.
I do not notice improvements in workflow automation as recent enhancements are managed by other teams; I am focused on using the tool to identify vulnerabilities.
I do not have an assessment of how multi-scanning and content disarm and reconstruction affect our data security operations.
I recommend implementing MetaDefender for its impressive features that maintain the health of the system. My overall review rating for MetaDefender is nine out of ten.
Alex Nigai
Content sanitization has improved file security and supports flexible policy-based workflows
Reviewed on Jun 05, 2026
Review provided by PeerSpot
What is our primary use case?
I am an integrator for MetaDefender. My usual use cases for MetaDefender involve connecting the products into the environment of the customer, including MetaDefender Core, ICAPs, endpoints, and all the related components.
What is most valuable?
I find the CDR, specifically the CDR ability, the most valuable aspect of MetaDefender so far. I appreciate the CDR because I can show customers how it works and demonstrate the effectiveness of this feature, and it is very helpful.
I did not pay much attention to the expanded file type and archive coverage feature initially. Could you explain what you mean by file type?
The enhanced reporting and audit visibility features are acceptable. Some customers of mine had problems with the health checks and monitoring of the logs, but it has improved, so that is very positive.
What needs improvement?
Most of the time, in our experience at Danet Communications, we work with government offices, and they need the CDR. However, because CDR is affecting files such as MSI and EXE files, they are always creating new passes of scanning. This is acceptable, but I would like OPSWAT to improve that, perhaps to decrease the impact when the process becomes slower. I am not sure if that is something that is possible.
There is something about MetaDefender that I think could be improved or enhanced, specifically regarding a feature request. Something that annoyed me was the less noticeable improvement from version 5.8.0 to 5.9.0 of MetaDefender Core. Now you have to search in the block if you want to create a blocklist, which is somewhat annoying when searching for your file. I may have just been accustomed to the old version.
From my experience, there are perhaps some improvements in workflow automation with the recent enhancements to policy orchestration and engine parallelization. However, there are many settings in the workflow that you cannot quickly understand what they are doing. Adding a question mark around them that provides a bit more information about that option would be beneficial.
For how long have I used the solution?
I have been working with MetaDefender for approximately six to seven months.
What do I think about the stability of the solution?
Regarding the reliability and stability level of MetaDefender, there are minor problems here and there, but nothing specific. Every time when help is needed, we receive the assistance.
When I say there are some troubles here and there, I mean there are different and unusual bugs or complications and things that cannot be connected to each other even though all the network configuration is acceptable.
What do I think about the scalability of the solution?
The scalability level of MetaDefender is good. It is learning and increasing with every patch, and that is acceptable.
How are customer service and support?
When I need help, I reach out first by trying to find information in the documentation. If I cannot find that, I go to the Ozi AI. If I see that the AI cannot help me, then I ask for an agent.
When it comes to my communication with agents, I find they are responsive and professional. A lot of the time, they are busy, so they cannot participate in calls or Teams meetings. However, if we schedule a meeting, they will attend, especially if it is very important.
How was the initial setup?
I usually participate in the initial setup, including the installation of MetaDefender. Most of the time, I send requirements for the server, and the customer has to create a server that meets what I have requested. After the customer has made the prerequisites, I can work with them on installing and connecting the products into their environment.
The initial setup usually looks like this for me: first, I need to send the prerequisites for every product, and I reference OPSWAT documentation to see what is needed, such as Visual Studio or Desknet. Then I send downloads of the products.
I usually find the initial setup has small challenges such as connectivity issues, but these are not on OPSWAT's side. They are more related to the customer's environment.
What other advice do I have?
I assess the effectiveness of MetaDefender in blocking or sanitizing content based on policy as very good. It contains a lot of file types, and most of the file types are included, so that is acceptable.
My impression of the detection rate provided by MetaScan multi-scanning is positive. I work mostly with the core, and my clients have not encountered false positives or those kinds of issues.
I evaluate the effectiveness of Deep CDR in reconstructing files safely and without signatures as good. I measure if it is effective by processing a lot of files, verifying that the content I want to be removed is being removed, and confirming that the hash is different.
To be honest, the file-based vulnerability assessment feature is more of a toggle option that we always enable, but we have not thoroughly tested it. I do see the effectiveness of this feature.
I think the adaptive sandbox analysis of MetaDefender works well. We do not have many customers using it, but from the customers who are using it, it functions effectively. Some of my customers describe its impact on analyzing suspicious files as adding additional layers of security. The reviews were positive, and while it may slow the scanning time slightly, that is understandable.
I rate this review an eight out of ten overall.
Paul Mhiripiri
Centralized endpoint security has strengthened patching, compliance and USB control across devices
Reviewed on May 29, 2026
Review provided by PeerSpot
What is our primary use case?
I have used MetaDefender for various use cases on my PCs at home and also enrolled it on some of my virtualized devices in my virtualized lab, which runs on Linux and Windows. I tried it on Windows 11, Windows 10, Ubuntu, and Kali Linux, and I enrolled the devices after trying quite a few use cases.
I blocked USB access on all the Windows machines, and it successfully blocked it, so I cannot use USB devices on these machines. I also utilize MetaDefender for patching my Windows devices, as it picks up outdated software and often identifies vulnerable third-party programs. Sometimes I need to patch the software or uninstall older versions before installing the new ones. I also use it for Windows updates, as it flags when my Windows updates and OneDrive application need to be updated. Additionally, it checks my browser extensions for status and compliance.
For malware protection, I am using McAfee, but if it has not scanned for some time, MetaDefender flags that too. I need to fine-tune my policy because it identifies McAfee, Windows Defender, and Microsoft Teams as unapproved products, so I will look into that. I have configured a policy, but since I am using a free version, I could not use DLP, and some intensive endpoint management functionalities are limited. It performs many tasks, including patching my devices, tracking critical issues, third-party vulnerabilities, and showing device locations on a graph. In brief, I am using it mostly for endpoint security.
I did not manage to enroll my IoT devices, including my child's device running on iOS and some Amazon products. I could not enroll my Fire Stick or monitor certain network devices. I initially thought I could enroll all those devices, including some children's IoT devices, but there seem to be limitations with Linux endpoint management as well. I hoped MetaDefender could help with parental controls for my Amazon Kids products.
I have not contacted technical support, though I thought I might need assistance fine-tuning my policy. When MetaDefender flagged some Windows DLL files as infections, I looked up information online and needed to whitelist them if they run directly from the Windows folder. If I could not resolve that, I would reach out for support, but I have not raised any tickets with MetaDefender yet.
What is most valuable?
MetaDefender is flexible because, for a free product, you can enroll up to 50 devices, and I have only used about eight devices so far. This flexibility allows you to explore its features before committing to a contract with MetaDefender, unlike other products that provide trial versions for a limited time.
I appreciate that you can use MetaDefender for various tasks, including patching, monitoring, vulnerability assessment, and compliance checking for up to 50 devices on the free license.
On the free version, I can only monitor device compliance, which includes the total enrolled devices and my compliance dashboard showing critical issues and warnings. It compiles data by desktops, laptops, virtual machines, servers, and mobile devices, including my enrolled Windows, Android, and one iOS device. The reports show compliant and non-compliant devices, allowing me to fine-tune my policies and group my devices for different policy applications.
There is no maintenance required on my end because the application on my endpoint automatically patches itself. When there is a new update, it handles the patching and alerts me when I am running the latest version. However, a feature I wish MetaDefender had is the ability to patch my devices centrally from my dashboard, including scheduling patches during off-peak times. I cannot provide a full review since I am using the free version, but based on my experiences, I would recommend MetaDefender to peers and companies using Windows endpoints.
What needs improvement?
I am not using the Expanded File Type and Archive Coverage feature, as it is not part of the free version. I was wondering if I could enroll more devices and replace McAfee with MetaDefender if it can serve as antivirus as well.
The initial deployment is straightforward, as there is an enroll link on the portal. Clicking that gives me options to enroll in MetaDefender Core, Endpoint, or Industrial File. I receive a QR code, and for devices like phones, scanning it enrolls them automatically. For Windows devices, it provides links to download the EML or EXE files, enabling easy Active Directory use. This straightforward enrollment process applies to Linux and macOS as well. However, for IoT devices, it is not so straightforward since it requires building the application from a downloaded file and running it, especially for Linux-based IoTs.
For how long have I used the solution?
I have been working with the solution for more than eight months.
What do I think about the stability of the solution?
MetaDefender does not crash and runs well without conflicts with other Windows or Linux applications, indicating that the developers have optimized its performance very well.
What do I think about the scalability of the solution?
I have only enrolled about eight devices, and I cannot comment on scalability for corporate networks with more than 500 endpoints since I have not tested it with larger numbers. I could consider testing on a licensed version to push patches automatically from the portal to assess its full capabilities. I would appreciate a trial period of one or two weeks for better testing of the full version features.
How are customer service and support?
I have not contacted technical support, though I thought I might need assistance fine-tuning my policy. When MetaDefender flagged some Windows DLL files as infections, I looked up information online and needed to whitelist them if they run directly from the Windows folder. If I could not resolve that, I would reach out for support, but I have not raised any tickets with MetaDefender yet.
Which solution did I use previously and why did I switch?
I have previously used other endpoint products like Fortinet's FortiEDR, but only in a virtualized environment. I could do similar use cases with that one as well.
How was the initial setup?
The initial deployment is straightforward, as there is an enroll link on the portal. Clicking that gives me options to enroll in MetaDefender Core, Endpoint, or Industrial File. I receive a QR code, and for devices like phones, scanning it enrolls them automatically. For Windows devices, it provides links to download the EML or EXE files, enabling easy Active Directory use. This straightforward enrollment process applies to Linux and macOS as well. However, for IoT devices, it is not so straightforward since it requires building the application from a downloaded file and running it, especially for Linux-based IoTs.
Which other solutions did I evaluate?
I have previously used other endpoint products like Fortinet's FortiEDR, but only in a virtualized environment. I could do similar use cases with that one as well.
What other advice do I have?
I am not using the Expanded File Type and Archive Coverage feature, as it is not part of the free version. I was wondering if I could enroll more devices and replace McAfee with MetaDefender if it can serve as antivirus as well.
On the free version, I can only monitor device compliance, which includes the total enrolled devices and my compliance dashboard showing critical issues and warnings. It compiles data by desktops, laptops, virtual machines, servers, and mobile devices, including my enrolled Windows, Android, and one iOS device. The reports show compliant and non-compliant devices, allowing me to fine-tune my policies and group my devices for different policy applications.