GateScanner Deep DetectoR
Static Malware Analysis for Every File — Without Execution, Without the Cloud
PRODUCTS GateScanner Deep Detector — Static Malware Analysis & Pre-Execution File Inspection | Sasa Software
GateScanner Deep Detector
Static Malware Analysis for Every File - Without Execution, Without the Cloud
File-based threats remain the dominant attack vector - arriving by email, removable media, supplier transfer, and web download as a matter of routine. Modern variants are built to evade: polymorphic packers mutate on each delivery, sandbox-aware malware stays dormant in virtual environments, and AI-generated payloads carry no prior signature to match against.
GateScanner Deep Detector (GSDD) takes a different approach. Rather than executing files or querying external services, it dissects each file structurally - parsing headers, extracting sections, isolating embedded objects - and assesses every component against more than 3,000 purpose-built detection rules. Every verdict is scored, ranked, and fully explained. Analysts see exactly which indicators drove the finding, and why.
Structural binary analysis
Deconstructs files to their base elements without executing a single instruction. Detects obfuscation, packing, and anomalous structure directly from the binary. Identifies files whose declared extension does not match their actual binary structure.
Multi-engine threat conviction with AI
Six independent detection layers run concurrently - format parsers, heuristic scoring, YARA rule matching, hash signatures, AI-powered ML classification, and optional commercial AV - producing a composite risk score with full per-indicator breakdown.
IOC extraction & attack chain detection
Extracts network indicators, C2 references, credential artifacts, and host-based IOCs across the full scan tree. Identifies multi-stage attack sequences spanning file boundaries - LNK-in-archive, macro-to-PowerShell, ISO MOTW bypass.
- Detonation-free, evasion-proof - files are never executed. No sandbox, no hypervisor, no detonation risk - and no execution environment for sandbox-aware malware to detect. Structural analysis is immune to timing loops and anti-analysis tricks.
- Signature-independent detection - verdicts derived from file structure and behavioral indicators, not hash databases. Zero-day variants, AI-generated payloads, and polymorphic code assessed on their own properties - no prior knowledge required, and no signature update cycle to fall behind on.
- Complete data sovereignty - fully offline. No file content, metadata, or telemetry leaves the host. Meets air-gapped, classified, and data-sovereign requirements without compromise.
- Broad binary file coverage - analyzes executables, binaries, installers, disk images, mobile apps, and container formats that sandboxes handle poorly and CDR cannot reconstruct.
- Lightweight and fast - single executable, no VM infrastructure, no database installation. Deploys in minutes. Static analysis completes in milliseconds per file at ingestion velocity.
| Engine | Function |
|---|---|
| Format parsers | PE, ELF, Mach-O, archives, scripts, email, DICOM and more. Flags extension spoofing and declared-vs-actual mismatches. |
| Heuristic engine | 30+ structural & behavioral indicators: entropy, section anomalies, import table characteristics, compiler fingerprints, obfuscation patterns. Weighted 0–100 risk score per file type. |
| YARA & signatures | 1,000+ curated YARA rules across 9 threat categories. Local MD5 / SHA-256 hash lookup - no external queries. |
| ML engine | AI-powered classification on learned structural features for zero-day and polymorphic threat detection. |
| Attack chain analysis | Correlates IOCs across nested file hierarchies. Detects multi-file sequences at depth. |
| AV engine (optional) | Cyren AV5 runs concurrently. A positive detection unconditionally forces a Critical verdict - cannot be overridden. |
- Explainable verdicts - every score is fully transparent: each contributing indicator cited by rule, threat category, and relative weight. No black-box outputs.
- Entropy heatmaps - packed, encrypted, and obfuscated sections identified visually across the file's byte distribution - structural signatures of concealment, surfaced at a glance.
- HEX viewer - raw binary content directly accessible for analysts who need to examine the underlying evidence rather than a processed summary of it.
- Archive tree - full extraction hierarchy with individual scores per node. Shows exactly where in a nested structure a threat resides.
- Full IOC extraction - network indicators, C2 patterns, credential artifacts, and host-based IOCs correlated across the complete scan tree.
- Export formats - JSON (SIEM/SOAR-ready), HTML (interactive), PDF (distribution), and directory summary reports for bulk scans.
Embedded CDR component
Integrated as the threat detection engine within the GateScanner suite - augments all CDR products with deep static analysis at every file ingestion point.
Standalone desktop client
Full analyst workstation application for forensic investigation and manual file scanning. Supports preset source and destination configurations for automated scan workflows - no network connection required.
Server-based service
Installed on-premise as a service, accessed via full REST API (OpenAPI / Swagger). Enables SIEM / SOAR integration, CI/CD pipeline scanning, and custom orchestration workflows.
OEM / embedded deployment
Available for integration into third-party security platforms and products as an embedded detection component.
…and more