Orion Malware, advanced file-based threat detection and analysis

Upload suspicious files to see their risk level and get a full report.

Enhance your detection and analysis capabilities

Why Orion Malware

Boost your team's efficiency

SOC/CSIRT teams leverage detailed reports to better understand threats and respond rapidly to incidents across critical infrastructure, military, healthcare and industrial sectors.

Detect zero-day and known threats

Identify malicious files through a multi-layered approach, combining reputation services, antivirus, YARA and Python rules, AI, agentless sandboxing and polymorphic analysis.

Easy integration

Orion Malware integrates with third-party applications via built-in (RestAPI, ICAP) and specific connectors (Harfanglab, Palo Alto, Gatewatcher...) to automate file submission.

Flexible deployment

Our solution can be deployed through On-Premise physical servers or SaaS, with a flexible range of models (S, M, L or cluster mode). It offers both online and offline modes.

Illustration of threats detection with Orion Malware

Threats detection with Orion Malware

Detect the most advanced malwares

Orion Malware detects malicious files across your entire infrastructure, including web proxies, firewalls, network probes, EDR, decontamination stations, email attachments, and both on-premises and cloud-based shared folders. Our solution is designed for complex and large-scale environments, offering a massive analysis capacity.

By leveraging multiple detection engines, Orion Malware identifies both known and unknown (zero-day) threats with high precision. Files can be submitted manually or via automated workflows. 

Our solution empowers CSIRT, CERT and SOC teams to customise their detection capabilities through customisable analysis workflow, detection rule management, agentless sandboxing, unpacking rules, reputation databases and YARA-based retro hunting. As a sovereign solution designed in France, we ensure strict data confidentiality.

Explore our detection capabilities through a live demo!

Discover the interface of our solution

On video

Explore the new features of Orion Malware in this video, which showcases our latest capabilities.

0:01:14

Orion Malware presentation

Strenghten your response capabilities

Threat investigation

Get detailed analysis reports

SOC, CSIRT and CERT teams can access detailed, engine-by-engine reports via the Expert portal, enabling them to better understand threats and respond rapidly to security incidents. These reports include behavioral graphs, malware activity timelines, MITRE ATT&CK classifications and exportable indicators of compromise (IoCs).

All employees can also be onboarded as 'sentinels', by checking if a file is safe through the Lite portal, a user-friendly interface enabling them to easily verify files before use.

Enable third-party integrations for automated file submission

Orion Malware provides built-in connectors:
- A full Rest API to automate and integrate with a third party application to submit files, get and search reports, download artefacts.
- ICAP response and request mode to submit files and get the results

We also designed specific connectors to automate file submission with third-party equipments (Harfanglab EDR, Palo Alto Cortex, Gatewatcher, MS-Exchange, OpenCTI, MISP...).

Download our Orion Malware brochure for detailed information on its detection and analysis capabilities.

Still have some questions?

Orion Malware

Find answers to frequently asked questions about our file-based threats detection and analysis solution.

What are the available versions of Orion Malware?

Orion Malware has 3 versions: All-in-One, All Static Analysers and Multi-AV. 

The All-in-One version includes:

  • Antivirus engines (up to 6)
  • Reputation lists
  • IP and URLs reputation analysis
  • Static scanner and AI models
  • Gorille, polymorphic analysis
  • YARA and Python rules 
  • Dynamic analysis in an agentless sandbox

     

The All Static Analysers includes: 

  • Antivirus engines (up to 6)
  • Reputation lists
  • IP and URLs reputation analysis
  • Static scanner and AI models
  • Gorille, polymorphic analysis
  • YARA and Python rules 

 

The Multi-AV version includes: 

  • Antivirus engines (up to 6)
  • IP and URLs reputation analysis
  • Gorille, polymorphic analysis

Who can benefit from using Orion Malware?

Orion Malware is tailored for SOC, CSIRT, CERT teams and malware analysts who would like to gain time by quickly detecting and analysing cyber threats, allowing them to focus on critical security incidents.

It provides cyber protection for all types of organisations, both public and private, such as critical infrastructure, energy, transportation, healthcare, public administration and defence, as well as the industrial sector

What is our licensing model?

We provide unlimited file analysis and unrestricted user access under a single license, ensuring you can meet all your cybersecurity needs and evolving operational demands. 

What are the key differentiators of Orion Malware?

Designed for large-scale environments, our solution offers a licensing model with unlimited file analysis and unrestricted user access. A single interface allows you to manage diverse use cases, from manual and automated detection to deep investigation and incident response.

Orion Malware guarantees total data confidentiality. No data is ever transferred to third parties, ensuring full sovereign control over your environment.

Do you offer technical support and regular software updates?

Yes, we provide continuous updating to the detection package, as well as technical and functional support (in French and English).

Illustration of Gorille with Orion Malware

Integration of Gorille into Orion Malware

Identify and classify malicious files with Gorille

Detection engine

Gorille, an innovative detection engine integrated into Orion Malware, is a sovereign French solution developed by Cyber-Detect. It specialises in the detection and classification of malicious Windows executable files

Gorille uses an AI-driven approach, formal methods and reverse engineering to identify zero-day attacks and polymorphic variants

By integrating Gorille into Orion Malware's analysis workflow, we aim to provide an even wider spectrum of detection with enhanced accuracy

Download our brochure for a complete overview of Orion Malware's capabilities, including our detection engines and analysis reports.

Explore the interface and features of our solution with a demo led by our cybersecurity experts.