GateScanner Deep DetectoR

Static Malware Analysis for Every File — Without Execution, Without the Cloud

GateScanner Deep Detector - Static Malware Analysis & Pre-Execution File Inspection | Sasa Software
! 10110 01101

GateScanner Deep Detector

Static Malware Analysis for Every File - Without Execution, Without the Cloud

Pre-execution static analysis across 300+ file types - including executables, binaries, installers, and disk images that cannot be sandboxed or reconstructed. No detonation. No cloud dependency. Verdicts in milliseconds.
Overview

File-based threats remain the dominant attack vector - arriving by email, removable media, supplier transfer, and web download as a matter of routine. Modern variants are built to evade: polymorphic packers mutate on each delivery, sandbox-aware malware stays dormant in virtual environments, and AI-generated payloads carry no prior signature to match against.

GateScanner Deep Detector (GSDD) takes a different approach. Rather than executing files or querying external services, it dissects each file structurally - parsing headers, extracting sections, isolating embedded objects - and assesses every component against more than 3,000 purpose-built detection rules. Every verdict is scored, ranked, and fully explained. Analysts see exactly which indicators drove the finding, and why.

Core capabilities

Structural binary analysis

Deconstructs files to their base elements without executing a single instruction. Detects obfuscation, packing, and anomalous structure directly from the binary. Identifies files whose declared extension does not match their actual binary structure.

Multi-engine threat conviction with AI

Six independent detection layers run concurrently - format parsers, heuristic scoring, YARA rule matching, hash signatures, AI-powered ML classification, and optional commercial AV - producing a composite risk score with full per-indicator breakdown.

IOC extraction & attack chain detection

Extracts network indicators, C2 references, credential artifacts, and host-based IOCs across the full scan tree. Identifies multi-stage attack sequences spanning file boundaries - LNK-in-archive, macro-to-PowerShell, ISO MOTW bypass.

Why static analysis - why GSDD
  • Detonation-free, evasion-proof - files are never executed. No sandbox, no hypervisor, no detonation risk - and no execution environment for sandbox-aware malware to detect. Structural analysis is immune to timing loops and anti-analysis tricks.
  • Signature-independent detection - verdicts derived from file structure and behavioral indicators, not hash databases. Zero-day variants, AI-generated payloads, and polymorphic code assessed on their own properties - no prior knowledge required, and no signature update cycle to fall behind on.
  • Complete data sovereignty - fully offline. No file content, metadata, or telemetry leaves the host. Meets air-gapped, classified, and data-sovereign requirements without compromise.
  • Broad binary file coverage - analyzes executables, binaries, installers, disk images, mobile apps, and container formats that sandboxes handle poorly and CDR cannot reconstruct.
  • Lightweight and fast - single executable, no VM infrastructure, no database installation. Deploys in minutes. Static analysis completes in milliseconds per file at ingestion velocity.
Detection engine architecture
EngineFunction
Format parsersPE, ELF, Mach-O, archives, scripts, email, DICOM and more. Flags extension spoofing and declared-vs-actual mismatches.
Heuristic engine30+ structural & behavioral indicators: entropy, section anomalies, import table characteristics, compiler fingerprints, obfuscation patterns. Weighted 0–100 risk score per file type.
YARA & signatures1,000+ curated YARA rules across 9 threat categories. Local MD5 / SHA-256 hash lookup - no external queries.
ML engineAI-powered classification on learned structural features for zero-day and polymorphic threat detection.
Attack chain analysisCorrelates IOCs across nested file hierarchies. Detects multi-file sequences at depth.
AV engine (optional)Cyren AV5 runs concurrently. A positive detection unconditionally forces a Critical verdict - cannot be overridden.
Risk verdicts
CLEANScore 0–59 · No indicators · cleared
LOW / MEDIUMScore 60–79 · Anomalies · analyst review
HIGHScore 80–99 · Strong indicators · quarantine
CRITICALScore 100 · AV or hash match · isolate immediately
Analyst output
  • Explainable verdicts - every score is fully transparent: each contributing indicator cited by rule, threat category, and relative weight. No black-box outputs.
  • Entropy heatmaps - packed, encrypted, and obfuscated sections identified visually across the file's byte distribution - structural signatures of concealment, surfaced at a glance.
  • HEX viewer - raw binary content directly accessible for analysts who need to examine the underlying evidence rather than a processed summary of it.
  • Archive tree - full extraction hierarchy with individual scores per node. Shows exactly where in a nested structure a threat resides.
  • Full IOC extraction - network indicators, C2 patterns, credential artifacts, and host-based IOCs correlated across the complete scan tree.
  • Export formats - JSON (SIEM/SOAR-ready), HTML (interactive), PDF (distribution), and directory summary reports for bulk scans.
Product form factors

Embedded CDR component

Integrated as the threat detection engine within the GateScanner suite - augments all CDR products with deep static analysis at every file ingestion point.

Standalone desktop client

Full analyst workstation application for forensic investigation and manual file scanning. Supports preset source and destination configurations for automated scan workflows - no network connection required.

Server-based service

Installed on-premise as a service, accessed via full REST API (OpenAPI / Swagger). Enables SIEM / SOAR integration, CI/CD pipeline scanning, and custom orchestration workflows.

OEM / embedded deployment

Available for integration into third-party security platforms and products as an embedded detection component.

File format coverage - 300+ parsers (partial list)
Container images.docker .tar .tar.gz .cpo .cpi + VM exports
Mobile - Android / iOS.apk .aab .dex .ipa .app .framework .pkg
Executables - Windows.exe .dll .sys .msi .scr .ocx .cpl .drv .efi
Email.msg .eml .mbox .pst .ost .mail
Executables - Linux / macOS.elf .so .dylib .app .macho .bundle .a
Web & scripts.html .js .ts .php .asp .ps1 .vbs .bat .py .rb
Archives - standard.zip .rar .7z .tar .gz .bz2 .cab .arj .lzh
Installer packages.msi .msix .appx .appxbundle .cab .nsis .wix
Disk & VM images.iso .img .vmdk .vhd .vhdx .qcow2 .ova .dmg
Macros & Office scripts.xlsm .docm .pptm .xla .xll .xlm .dotm
Office & PDFs.pdf .doc(x) .xls(x) .ppt(x) .odt .rtf .csv
Certificates, config & other.pem .p12 .xml .yaml .reg + media, firmware, fonts

…and more

10110100 01001011 11010010 00101101 ! GATESCANNER
GateScanner Deep Detector
Static Malware Analysis & Pre-Execution File Inspection
Key specifications
PlatformWindows x64
DeploymentSingle executable
Analysis speedMilliseconds / file
File formats300+ parsers
Detection rules3,000+ / 1,000+ YARA
Recursion depth1–999 levels
Cloud dependencyNone - fully offline
Detection engines6 concurrent
InterfacesREST API · CLI · GUI · Desktop

Try our award-winning solution today !

Scroll to Top
Scroll to Top