Overview
OPSWAT MetaDefender Core Security Dashboard
The dashboard displays blocked threats and processed objects, with a donut chart summarizing file types detected by MetaDefender Core.
OPSWAT MetaDefender Core Security Dashboard
OPSWAT MetaDefender Core Workflow
OPSWAT MetaDefender Core Archive Extraction

Product video
MetaDefender Core - Advanced Threat Detection and Prevention for Critical IT and OT Environments
MetaDefender Core is an advanced threat prevention platform that neutralizes malware, ransomware, and zero-day attacks before they infiltrate your environment. It combines AI-enhanced technologies, including Predictive AI, Deep CDR, Metascan Multiscanning, AI Content Inspection, Adaptive Sandbox, Proactive DLP, Threat Intelligence, File-based Vulnerability Assessment, SBOM, and Country of Origin, to secure every file across every channel. Whether protecting uploads, downloads, network transfers, or shared documents, MetaDefender Core helps organizations maintain compliance, reduce operational risk, and build trust. Unlike reactive tools, it proactively analyzes and sanitizes potentially malicious content before execution, enforcing zero trust at the file level.
Note: This is a BYOL listing for MetaDefender Core. To inquire about a Private Offer, please contact us at apn-sales@opswat.com .
Core Technologies and Buyer Outcomes
Predictive AI uses machine learning to analyze deep file structures and block risky files instantly, without detonation or runtime analysis.
Metascan Multiscanning scans files with 30+ anti-malware engines simultaneously, detecting more than 99% of known and unknown threats and reducing SOC alert fatigue.
Deep CDR (Content Disarm and Reconstruction) recursively sanitizes and rebuilds 200+ file types, neutralizing embedded threats while preserving full file usability.
AI Content Inspector flags AI-generated content, document manipulation, and fraud indicators in images, PDFs, and text-bearing files at ingest, returning policy-ready verdicts.
Proactive DLP removes, redacts, or blocks sensitive data in 125+ file types before content leaves the organization, supporting GDPR, HIPAA, and PCI-DSS compliance.
Adaptive Sandbox detonates and analyzes suspicious files in a controlled environment to improve zero-day detection without risking production systems.
Threat Intelligence extracts sandbox-derived Indicators of Compromise and applies similarity scoring to identify novel variants and campaign-level relationships, with 99.6% detection accuracy.
Reputation classifies files as known good, known bad, or unknown by comparing hashes against a continuously updated database, plus metadata and contextual analysis.
File-based Vulnerability Assessment identifies vulnerabilities in installers, binaries, and applications before installation.
SBOM generates software bills of materials and identifies vulnerabilities in source code and containers, supporting EU CRA, NIS2, EO 14028, and NIST compliance.
Country of Origin determines the true origin and vendor of PE, MSI, and self-extracting files, then blocks or escalates files from high-risk sources.
Industry Use Case: Federal Agency Document Upload Portal
Federal agencies and critical infrastructure operators use MetaDefender Core to analyze citizen-submitted documents at upload portals before files reach backend storage. Every uploaded file passes through multi-layered inspection, neutralizing zero-day, ransomware, and malicious payloads embedded in PDFs, Office documents, or images before they enter the trusted environment. This reduces compliance burden and eliminates false positives from single-engine scanning.
AWS Deployment Options
MetaDefender Core deploys on AWS via Amazon Machine Image (AMI) on EC2 for high-throughput scanning, containers on Amazon EKS for horizontal scaling, or standard EC2 instances sized to scan volume. REST APIs and ICAP protocol enable integration with existing security workflows, web application firewalls, proxies, and storage systems. MetaDefender Core adapts to on-premises, cloud, containerized, air-gapped, or hybrid environments.
Getting Started
Contact apn-sales@opswat.com to request a private offer or schedule a guided demo. Once subscribed, launch the MetaDefender Core AMI on your chosen EC2 instance, activate your license, configure scanning policies via the management console, and integrate using REST API or ICAP protocol.
Compliance and Framework Alignment
MetaDefender Core helps organizations align with Zero Trust Architecture and frameworks including GDPR, HIPAA, and NIST Cybersecurity Framework.
Next Steps
- Request a Guided Demo: see MetaDefender Core in action with a solutions engineer
- Start a 30-Day Pilot: evaluate full functionality in your environment
- Contact Us: email apn-sales@opswat.com for a private offer
Highlights
- Metascan Multiscanning with 30+ anti-malware engines detects over 99% of known and unknown threats while Deep CDR recursively sanitizes 200+ file types to neutralize embedded threats and zero-day exploits - reducing false negatives, eliminating SOC alert fatigue, and ensuring files are safe before execution.
- Deploys flexibly on AWS via AMI on EC2 instances, containers on Amazon EKS, or air-gapped environments. Integrates seamlessly into existing architectures through REST APIs and ICAP protocol - connecting with web application firewalls, proxies, storage systems, and custom applications without requiring infrastructure redesign. Supports on-premises, cloud, hybrid, and disconnected deployments.
- Helps organizations align with zero-trust architecture and regulatory frameworks such as GDPR, HIPAA, NIST, etc. by reducing sensitive data exposure through Proactive DLP and strengthening supply chain visibility with SBOM generation. Trusted by governments, critical infrastructure operators, and over 2,100 global organizations.
Details
Introducing multi-product solutions
You can now purchase comprehensive solutions tailored to use cases and industries.
Features and programs
Trust Center
Buyer guide

Financing for AWS Marketplace purchases
Pricing
How can we make this page better?
Legal
Vendor terms and conditions
Content disclaimer
Delivery details
64-bit (x86) Amazon Machine Image (AMI)
Amazon Machine Image (AMI)
An AMI is a virtual image that provides the information required to launch an instance. Amazon EC2 (Elastic Compute Cloud) instances are virtual servers on which you can run your applications and workloads, offering varying combinations of CPU, memory, storage, and networking resources. You can launch as many instances from as many different AMIs as you need.
Version release notes
Additional details
Usage instructions
Accessing MetaDefender web-based management console:
- To access the MetaDefender Core web-based management console for the first time, connect to the IP address of the instance using a browser (e.g. http://localhost:8008 ). You will then be guided through the setup wizard to configure, license and use the product.
Connecting to MetaDefender Core AMI Instance console:
- To connect to your MetaDefender Core command-line console, you will need to use RDP. For further information about the standard AWS method of connecting to an instance, see information described here: Connect to your Windows instance - Amazon Elastic Compute Cloud
- Operation of the product is covered here: https://docs.opswat.com/mdcore/operating .
Health and Monitoring
- Maintenance information can be found here: https://docs.opswat.com/mdcore/operating/regular-maintenance
Additional Details
- There are no additional external resources that are required for the product to function.
- Customer data is not collected while running this product.
- To create custom AMI from this OPSWAT AMI is covered here: https://docs.opswat.com/mdcore/cloud-deployment/single-ec2-deployment#opswat-metadefender-ami-from-marketplace-usage
Support
Vendor support
OPSWAT provides technical support for MetaDefender Core customers through the OPSWAT support portal at https://my.opswat.com/ . Customers can submit support tickets, access product documentation, and manage their licenses through this portal.
Contact for Sales and Private Offers: For pricing inquiries, private offer requests, guided demos, or pilot evaluations, contact the OPSWAT AWS sales team at apn-apn-sales@opswat.com .
Self-Service Resources:
- Product documentation and deployment guides: https://www.opswat.com/docs/mdcore
- OPSWAT Academy free training (https://www.opswat.com/academy )
- Knowledge base articles for troubleshooting and configuration: https://www.opswat.com/docs/mdcore/troubleshooting
- REST API documentation for integration support: https://www.opswat.com/docs/mdcore/metadefender-core
Getting Help:
For technical issues including product configuration, scanning policy setup, integration troubleshooting, license activation, and operational questions, submit a ticket through the support portal. For billing questions or refund requests related to your AWS Marketplace subscription, contact apn-sales@opswat.com .
Important Note: This is a contract listing for use with AWS private offers only. Pricing varies depending on customer environment, scan volume requirements, and deployment configuration. Contact apn-sales@opswat.com to discuss your requirements and receive a tailored private offer.
AWS infrastructure support
AWS Support is a one-on-one, fast-response support channel that is staffed 24x7x365 with experienced and technical support engineers. The service helps customers of all sizes and technical abilities to successfully utilize the products and features provided by Amazon Web Services.
Similar products
Customer reviews
Centralized endpoint checks have secured global access to sensitive corporate resources
What is our primary use case?
Before accessing the company's protected resources, it is being scanned through MetaDefender Endpoint, which scans the local operating system and machine before the request actually hits the company's protected resources.
MetaDefender Endpoint has been installed in the Windows operating system machine, and before accessing any protected resource of the company, MetaDefender scans the request and the resources, and it even scans the local machine. If there is any vulnerability or any kind of malware, then it immediately blocks the resource and does not allow access to the protected resource for the company. In this case, it is the company's protected resource, so access is not allowed. It checks the software and checks the various software that is installed in the machine, and if all are acceptable, then only MetaDefender is allowed to access the protected resources.
For companies that are widely distributed and have resources with company employees widely located across the world, it provides a centralized, secure platform before accessing any protected resource. This is a mandatory software that everyone should install in their machine and ensure that it passes all the quality checks, making it a strong platform in terms of security and securing protected resources.
How has it helped my organization?
MetaDefender is fundamentally a security platform. All resources that are company proprietary resources are secured with MetaDefender Endpoint, and this is what was desired at the company level. It is mandatory for each and every resource in the company located across the globe to be scanned by MetaDefender Endpoint before accessing these protected resources.
All employees in the organization are keeping their machines up to date; all software is regularly upgraded. For example, browser versions or other software such as Notepad++ are being upgraded. They are also conducting full Windows scans, meaning they are doing complete security full scans on their machines on a monthly basis because this is set at the organization security policy where it is mandatory to scan the machine once a month. These security policies are implemented, and MetaDefender is valuing these policies and ensuring that all employees are aligning with the security policy.
What is most valuable?
MetaDefender checks all the software and its latest version, and whether the local software that is installed is aligned with the organization policy that is set by the organization security administrator. MetaDefender passes all this information and checks against those policies that are being set and determines whether the installed software is aligned with the organization policy or not. For example, if any deprecated software or any software that has any kind of malware is in the machine, then it immediately highlights and stops accessing those protected resources.
MetaDefender is always on at startup; it must be enabled during startup of the operating system, and when accessing any protected resource, after authorization and authentication, it immediately checks whether the resource being accessed is allowed for access, and it scans all the software. Whether it is a browser version such as Chrome browser, or if it is having a deprecated or older version, or any operating system software such as WinRAR or Notepad++, any software that is deprecated or has an older version, it will immediately flag that as an error and will not allow access to the protected resources.
This is quite helpful in terms of securing resources; it immediately brings those vulnerabilities or incompatibilities in the system to attention. It also provides the feature to check the status of the operating system or machine status immediately. There is an icon at the taskbar; clicking and rechecking the status of MetaDefender Endpoint shows the current status. If all are acceptable, then it will confirm that all is well, and access to the protected resources can proceed. If there is any issue, it will flag that on the screen when rechecking the status.
MetaDefender highlights all the vulnerabilities the moment of accessing the protected resources, so it scans all the files in the system and brings those issues when clicking the recheck button.
It does the auditing of the local machine and maintains awareness of what is occurring on the machine, specifically from the security perspective. If there is any vulnerability or any kind of malware being deployed in the machine, it immediately stops access to those protected resources.
What needs improvement?
If there is any major vulnerability, then it is understood that it should not allow access to the protected resource. However, if the vulnerabilities are not serious and are at the information or warning level, then MetaDefender should allow access to those protected resources. For example, if using an older Chrome browser version, it should not be a significant security issue. Similarly, older version Notepad++ represents low priority issues that MetaDefender could still allow employees to access the protected resources, but currently, MetaDefender treats these small issues as high priority.
MetaDefender will not automatically open the screen and display vulnerabilities unless the recheck button is clicked, which is something that could be improved. The moment the operating system or machine is opened, it should highlight any issues if there are vulnerabilities rather than waiting for the recheck button to be clicked.
The recheck button needs to be clicked every time. Additionally, low priority issues are taken very seriously and considered blockers. For example, outdated browser versions or any software in the machine that does not have the latest version could be considered low priority if the software is not critical.
The full scan takes considerable time; a complete Windows full scan takes almost 12 hours because it has billions of files. The full scan is time-consuming, and if MetaDefender could scan it more quickly and provide results faster, that would be an improvement.
Regarding improvements, low priority software that is highlighted as a blocker could be reworked to still allow the user to access the protected resources. Additionally, MetaDefender could introduce some kind of workflow or user interface which highlights all issues or vulnerabilities in one place rather than requiring clicking the recheck button and navigating through the browser.
For how long have I used the solution?
This product has been in use for two years.
What do I think about the stability of the solution?
MetaDefender is stable, but it brings or highlights items which are low priority, and software upgrades need to occur very frequently because it checks all the minute details in the operating system and system and brings them forward, necessitating software upgrades.
What do I think about the scalability of the solution?
MetaDefender handles the scale well. There are quite a lot of employees, more than 50,000 employees, and all are using it, making it a quite scalable platform.
How are customer service and support?
Customer service has not been contacted yet because it is a quite stable environment and a stable platform. MetaDefender highlights all the issues and even guides how to resolve vulnerabilities, for example, by installing upgraded software or conducting a full scan. It is quite comprehensive in explaining the issues that are currently encountered.
What was our ROI?
MetaDefender Endpoint has provided benefit from its use. The company's resources are fully protected and secured; no unauthorized access can reach the protected resources. All resources are now secured, and MetaDefender Endpoint can be trusted in this area.
What's my experience with pricing, setup cost, and licensing?
The setup and pricing are managed at the organization level, and the security department or the infrastructure department would have better knowledge of costing and pricing.
Which other solutions did I evaluate?
Previously, the authentication and authorization method was using Azure Active Directory, or Azure Entra ID, and now MetaDefender is also used along with Azure AD.
What other advice do I have?
From the security perspective, I would rate it an eight. MetaDefender is on-premises and managed by the company's platform. For any company where resources are widely located across the globe, MetaDefender Endpoint should be considered as one of the security platforms that ensure all protected resources are very much secure.
Advanced file sanitization has strengthened threat detection and protects daily content workflows
What is our primary use case?
My main use case for MetaDefender is for security purposes, as we are a cybersecurity team, and currently we are using it for purposes such as antivirus scanning and other security measures.
In my day-to-day work, we are working with a company called Opswat, and we have devices, so to keep everything clean and clear, we are using MetaDefender as an antivirus firewall. We are inserting this MetaDefender chip for scanning purposes and using it as a firewall as well, but I do not have much knowledge about it because I am in a non-technical role right now.
In terms of using MetaDefender, we are utilizing it for threat detection, multi-scanning, and enterprise security.
How has it helped my organization?
MetaDefender has impacted my organization positively by adding an extra layer of security to our file and content handling process, and through its CDR, it ensures that files are sanitized before they reach our environment, which has improved our security posture.
I have noticed that the confidence and security of file processing have improved, with multi-engine scanning providing threat detection, and the security checks help us identify malicious files before they enter our environment, although I have not yet observed a specific, quantified business impact.
What is most valuable?
In my experience, MetaDefender offers a Deep CDR, and other major strengths include multi-scanning, Tri-tech AI, Adaptive Sandbox, Proactive DLP, and file vulnerability assessment.
Out of those features, I find myself relying on Deep CDR the most because it is one of MetaDefender's key differentiators; it does not depend only on detecting known malware but sanitizes and reconstructs files to prevent potentially malicious content, including zero-day threats, from reaching the environment.
Regarding MetaDefender's AI features, I think it handles data responsibly and keeps things secure by providing protection in multiple layers through malware scanning, threat detection, and content sanitization, which helps organizations manage security risks while maintaining a good balance between security, control, and compliance.
I find MetaDefender's AI capabilities to be reliable and useful as an additional layer of threat detection, with results that have been generally consistent and provide useful insights when analyzing files, though I have not used the AI capabilities long enough to independently measure accuracy.
My impression of the detection rates from MetaDefender's Metascan Multi-scanning has been positive; using multiple scanning engines provides broader coverage and greater confidence that potential threats will not be missed, and while I have not independently measured the detection rate, the results I have seen are consistent and useful for identifying potential malicious files.
I assess Deep CDR as highly effective in reconstructing files safely and without signatures because it focuses on safely reconstructing files rather than relying only on traditional malware signatures, which is particularly valuable for handling unknown or potentially zero-day threats while keeping reconstructed files usable.
I think the file-based vulnerability assessment feature is valuable because it helps identify potential vulnerabilities before files or applications are deployed, providing an additional preventive security layer that helps organizations address risk earlier rather than discovering them post-deployment.
We are using the reporting and audit visibility features to gain better visibility into scanning activities and results, which help provide a clearer record of what has been scanned and the outcomes, aiding in tracking and audit purposes from an operational perspective.
What needs improvement?
One area where MetaDefender could improve is by making the user experience more intuitive, especially for new users, with clear guidance, simpler navigation, and a more detailed explanation of scan results and outcomes, which would enhance the effectiveness for users, while better onboarding and learning resources would help users get familiar with the different features more quickly.
The usability and onboarding are my main concerns, as I do not have much overview on the technical aspects.
For how long have I used the solution?
I have been using MetaDefender for two to three months.
What other advice do I have?
MetaDefender offers strong security capabilities and multiple layers of threat detection, but since I am still relatively new to this platform, I would explore more of its features before giving it a higher rating. Even though MetaDefender provides a strong, multilayered security and is quite useful and comprehensive, the user experience on onboarding and the clarity of scan results could be simpler, especially for new users.
My advice to organizations looking into using MetaDefender is to seek an additional layer of security around file and content handling, as it is a great choice with multi-engine scanning, CDR, and vulnerability assessment capabilities providing good overall coverage. It is important to clearly understand your organization's security requirements and take time to explore the different features and integrations to get the most value from the platform.
I would rate MetaDefender as an eight out of ten.
Advanced file checks and deep sanitization have prevented threats at the entry point
What is our primary use case?
MetaDefender prevents organizations from file-borne malware and file-borne threats by preventing threats at the entry point itself.
What is most valuable?
MetaDefender's threat detection ratio is quite high because it uses multiple anti-malware engines. Sanitization helps eliminate typical zero-day threats such as macro-based attacks and script-based attacks.
Deep CDR feature in reconstructing files has provided significant value to customers. When they receive phishing links, dummy QR codes, or embedded actions defined on documents, Deep CDR removes all those potential threats.
MetaDefender supports all expanded file type and archive coverage features, which means most of the 4,000-plus file types are covered. It provides a quite deep scanning process. Archive extraction gives more visibility of the files.
The file-based vulnerability assessment feature is straightforward. When downloading a file from the internet and scanning it, information about known vulnerabilities is provided. It gives advanced information about the vulnerability.
With MetaScan multi-scanning feature, certain web shell attacks can be detected which others cannot. Whether it's 8 anti-malware engines or 20, the detection ratio and rate are quite good.
What needs improvement?
Reporting still requires improvement, but otherwise the solution is excellent. Other areas include centralized management, providing the capability to manage all instances from a single console, centralized reporting, and integration through central management.
For how long have I used the solution?
I started working with MetaDefender in 2021.
What do I think about the stability of the solution?
Uptime is 99.99%, so it is 99% stable and reliable.
What do I think about the scalability of the solution?
Scalability with MetaDefender is very good.
How are customer service and support?
Support is excellent. Technical support from OPSWAT is excellent.
Which solution did I use previously and why did I switch?
We are not working with Trend Micro, also called today Trend AI Vision One, which is hardcore competition. We are purely working on MetaDefender.
How was the initial setup?
Installation for the deployment of MetaDefender is straightforward.
What was our ROI?
Many threats are prevented before entering the organization with MetaDefender. It definitely saves more effort for the SOC team if threats are being eliminated at the entry point itself, allowing them to focus more on other things.
What's my experience with pricing, setup cost, and licensing?
MetaDefender is affordable. It is flexible, and pricing-wise there are no concerns with this solution.
Which other solutions did I evaluate?
When comparing MetaDefender to other solutions, I compare it to Trend Micro, Broadcom, and Check Point for email.
What other advice do I have?
MetaDefender is leading with respect to competitors as an all-in-one platform because no other tool has all the platform built-in.
For example, MetaDefender cannot identify the source itself, but if a file is scanned, the complete detail of the scanning can be seen.
If someone modifies a policy, adaptive sandbox analysis takes a little bit of time, but it gives accuracy up to 99%.
Continuous improvement that OPSWAT is doing with enhancements made to policy orchestration and to engine parallelization demonstrates that OPSWAT is adapting.
I rate this solution a 10.
Which deployment model are you using for this solution?
If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?
Multi-layered file analysis has strengthened our email defense and reduced manual SOC effort
What is our primary use case?
My main use case for MetaDefender is for multi-scanning purposes, including Deep CDR, sandbox-based analysis, and protecting the organization from malware and other file-based threats delivered through email, particularly suspicious or unknown attachments. I primarily view it as an additional inspection layer for email attachments, using its multi-scanning capability to analyze files with multiple detection engines. The Deep Content Disarm and Destruction capability is also valuable because it can remove potentially malicious content from supported files and provide a safer version for the user. From a SOC's perspective, this is particularly useful for handling files that may bypass traditional signature-based security controls while email filtering is happening. It gives us additional confidence when dealing with documents such as PDFs and Office files and all other materials that we receive through email. MetaDefender prevents malicious or weaponized files from reaching users while reducing the risk associated with unknown, zero-day file-based threats.
What is most valuable?
The best features of MetaDefender include multi-scanning, multi-layered scanning of any email or attachment, the CDR feature, and the sandboxing analysis capability. The multi-scanning feature is particularly useful because a file can be checked against multiple antivirus engines instead of relying on a single detection engine. Deep CDR is one of the strongest features because instead of only detecting whether the file is malicious, it can sanitize supported files by removing potentially dangerous content and reconstructing a safe version. This is especially useful for documents and email attachments where we still need to allow the business to work with the file. The adaptive sandbox is another valuable feature for files that require deeper behavior analysis, providing another layer for identifying suspicious or malware-like content that may not be obvious through the traditional scanners that we use.
MetaDefender has a positive impact by adding multiple layers of file scanning, email classification, and attachment investigation in a more efficient way. Instead of just relying on the verdict from our primary email or endpoint security solution, we can use MetaDefender to get additional analysis across multiple engines. This is especially helpful when dealing with suspicious or previously unseen files, zero-day attack files. Deep CDR has also been useful from a risk reduction perspective because potentially dangerous content can be removed from supported files while still allowing users to work with a usable version of the document. Overall, MetaDefender has a positive impact on analysis and detecting suspicious files, leading to greater confidence in our environment. It has also helped reduce some of the manual efforts involved in determining whether the attachment is safe or not.
What needs improvement?
MetaDefender is quite better in all aspects it has been designed for. We could enhance the user interface and user experience, as the platform has many security capabilities, but some configuration and policy management tasks can take time to understand, especially for someone using the product for the first time. I would appreciate more intuitive reporting and dashboards. The security information is useful, but making key metrics, detection trends, false positives, and remediation actions easier to understand would help a SOC team quickly identify areas requiring attention. Another area for improvement would be reducing false positives and improving processing time for large or complex files, which sometimes may require additional manual review. The CDR is a very useful tool, but clearer handling and exception management should be implemented when sanitizing legitimate files. Automation and integrations could also be enhanced, particularly around recommending appropriate actions based on scan results and simplifying integration with other security tools.
For how long have I used the solution?
We have been using MetaDefender for more than two years.
What do I think about the stability of the solution?
From my overall experience, MetaDefender is a very stable and reliable product when it comes to the outcomes of file analysis and email attachments received. In my day-to-day experience, I have not encountered any major stability issues that would significantly affect email or file security operations. The core functions, such as multi-scanning, sandboxing, and file inspection, have been consistent. Once the policies and integrations are configured properly, there is minimal ongoing maintenance required to keep the solution operational. I would monitor its performance when handling very large or complex files, as scanning can sometimes take longer.
What do I think about the scalability of the solution?
MetaDefender can handle any traffic and is suitable for any organization regardless of size. With our security requirements, we can achieve this with the existing environment and scale without requiring redesign or re-architecture. Its main advantage is the flexibility in deployment, allowing it to be deployed in the cloud or on-premises. Additional instances can be added as email volume and the number of protected users increases. Overall, I consider MetaDefender to be highly scalable and suitable for any growing organization of any size, with the main requirements being proper planning for traffic and security workloads.
How are customer service and support?
Their customer support is outstanding. Whenever we raise any support case, they provide complete structural descriptions and solutions to the problems we report, and they resolve issues on the spot. I would rate them nine out of ten.
Which solution did I use previously and why did I switch?
We were previously using Evinent as a security tool, and we incorporated MetaDefender for extensive EDR plus email security.
How was the initial setup?
The decision to switch to MetaDefender was mainly taken by higher management, and as a SOC analyst, I was not involved in the evaluation of other options.
What about the implementation team?
We are a customer.
What was our ROI?
We have reduced some of our manual effort and saved time, even investing additional time on zero-day attacks. In file analysis, we have sometimes saved a lot of time, while also spending a little more on suspicious files. Overall, using MetaDefender has been beneficial and can be justified as a positive investment.
Which other solutions did I evaluate?
The decision to switch to MetaDefender was mainly taken by higher management, and as a SOC analyst, I was not involved in the evaluation of other options.
What other advice do I have?
If you are looking for a solution that enhances your email security or your EDR product, and if you are considering more security solutions that can protect both combinedly, I would recommend MetaDefender as one of the best tools. Its features include multi-scanning, Deep CDR, sandboxing, and file investigation, which are essential for effective detection while minimizing false positives and scanning times. Integration with the existing environment is also important; if you are using Microsoft 365, ensure that flow connectors and policies are planned and tested before moving into production. I would also check for potential conflicts or mail loops if another third-party email security solution is already deployed. Another recommendation is to spend time on policy tuning and user group segmentation. MetaDefender allows policies to be prioritized and applied to specific audiences, making administration much easier as the environment grows. I would recommend this approach as well. My overall rating for MetaDefender is eight out of ten.
Central console has secured all API file traffic and supports multi-engine endpoint scanning
What is our primary use case?
My main use case for MetaDefender involves the Central Management Console, core service, and ICAP service.
In my day-to-day work, I use MetaDefender to scan endpoint security, but we did not have a product to cover API traffic scans. MetaDefender OPSWAT provides that solution, and also the ICAP scans. It is a really good product. We have customers sending all the files via API calls, and they will be scanned by OPSWAT for antivirus scan and also Data Loss Prevention scan. It is a great product.
We have more than ten different vendors connected to MetaDefender for scanning, and it is working very well.
What is most valuable?
The best features MetaDefender offers are the ICAP Scan and API Scan. For the ICAP Scan and API Scan, they stand out to me because they are easy to manage and can also adopt multi-clients at the same time and scan by seven different scan engines and different antivirus signatures scan.
MetaDefender positively impacts my organization by filling the gap, as we do not have any other product that can scan API calls. It has helped to improve compliance requests. It also scans all the API traffic and makes sure the API traffic is secured and clean.
What needs improvement?
MetaDefender can be improved by upgrading the Linux version, which is using many free tools such as MongoDB, Postgres, and OpenSSL. It can be easily targeted by hackers. If MetaDefender can upgrade those free versions of products regularly to cover those vulnerabilities, that would be beneficial. Regular patching, upgrades, and CVE coverage would be beneficial, especially because AI attacks can exploit any vulnerabilities, CVEs, and zero-days from those free MongoDB tools, which are an easy target.
Regarding MetaDefender's AI capabilities, I do not see much AI integration with MetaDefender at this moment. My thoughts on its accuracy and reliability of output are that it relies on signature-based antivirus scan, which is not sufficient for AI-kind vulnerabilities or hacking. This part needs improvement.
For how long have I used the solution?
I have been using MetaDefender for five years.
What do I think about the stability of the solution?
MetaDefender is a stable product.
What do I think about the scalability of the solution?
MetaDefender's scalability is great. We can increase the central management server by adding more CPU, RAM, and disks, and we can add more clients to the scan and create a policy for them. It has great scan capability and great extendibility.
How are customer service and support?
Customer support is great. I have worked with the Vietnam team quite a few times, and they are always very active, proactive, and offer remote sessions quite a few times. It is a great service.
Which solution did I use previously and why did I switch?
Previously, we were using McAfee antivirus scan servers for ICAP filters, but with increasing API call requests, MetaDefender filled that gap and provided the API call scan service, which is great.
How was the initial setup?
We tried Deep CDR for a while, but it was consuming a lot of CPU and RAM, so we stopped that.
What about the implementation team?
With the recent enhancements to policy orchestration and engine parallelization, we upload all MetaDefender detection events into Splunk, and our incident response team is using the Splunk SOAR product to automate all those detections and reactions. It is a Splunk integration. I assess the effectiveness of the solution in blocking or sanitizing content based on policy by noting that we are using Splunk, and the CISO and the incident response team are using the Splunk SOAR console to perform automation detections and reactions.
What was our ROI?
I see a return on investment.
What's my experience with pricing, setup cost, and licensing?
My experience with pricing, setup cost, and licensing is that the cost and license fee is increasing every year.
Which other solutions did I evaluate?
Before choosing MetaDefender, we did not evaluate other options. We mainly wanted to use OPSWAT for API call scans, and we could not find any other product in the market at that time.
What other advice do I have?
My advice to others looking into using MetaDefender is that it is a great product. We are only using the on-premise product because of company policy, as we are not allowed to upload our customer data into the public cloud. I think the hybrid cloud and private cloud product would be beneficial. That is the trend, so using hybrid cloud mode is a beneficial option for all other companies. We are currently still using the on-premise product.
We are not using the enhanced reporting and audit visibility features at this time.
The file-based vulnerability assessment feature is great because it can scan using seven different antivirus scan engines, but with AI attacks now, signature-based detection is not sufficient, which is a problem for all antivirus product vendors.
I give MetaDefender an overall rating of ten out of ten.