Inspect uploaded files
the moment they land.
MalScan automatically analyzes files stored in Amazon S3 and determines whether they are suspected malware. It identifies each file's format from its content and sends it to analysis dedicated to that format: executables, Office documents, PDFs, scripts, archives and more. Each verdict comes with reasons and IOCs (indicators of compromise), mapped to MITRE ATT&CK techniques. Results can also be fed into your SIEM or threat intelligence platform via the API or a STIX / TAXII feed.
Challenges
Sound familiar?
Upload features become an entry point
Attachments to contact forms and application pages become a path for bringing malware into your organization.
No basis for the verdict
Being told only that a file is “dangerous” does not let you decide how to respond if you do not know what the problem is.
Building inspection takes effort
Building S3 event notifications, queues and per-format analysis yourself takes a lot of effort.
Features
MalScan key features
01Automatic inspection on S3 upload
Register a bucket and S3 event notifications are configured automatically, so every file placed there is inspected. You can register multiple AWS accounts and buckets.
02Format detection by content
The format is determined from the leading bytes of the file, not the extension, so files with a disguised extension are still analyzed as their true format.
03Per-format analysis
Executables, Office documents, RTF, PDF, scripts, HTML, shortcuts, disk images, OneNote, MSI, Android, Java, images and more are each analyzed from a dedicated perspective.
04Archives inspected inside
Files inside archives are extracted and inspected, and the highest-risk result becomes the overall verdict. Extraction volume is capped to guard against decompression bombs.
054-level verdicts with reasons
Files are classified into 4 levels (malicious, suspicious, low-confidence suspicious, likely benign) with reasons, hash values, entropy and IOCs.
06Mapped to MITRE ATT&CK
Files judged malicious or suspicious are automatically mapped to MITRE ATT&CK techniques based on what was detected. There is no additional charge.
07AI IOC triage and hunting queries
AI organizes IOCs and creates Splunk and KQL hunting queries (optional). It runs on Amazon Bedrock in your AWS account or with your Anthropic API key.
08API and IOC feed
Use an API key to submit files for inspection and retrieve results. Detected IOCs are delivered via STIX 2.1 / TAXII 2.1 for ingestion into a SIEM or threat intelligence platform.
Use cases
Build inspection into
wherever files come in
Files from outside arrive through many paths: web upload features, S3 buckets, attachments sent to employees and more. MalScan offers 3 entry points (automatic S3 inspection, the API and the console), so you can build it into each path.
Upload features in web services
In forms that accept application documents, resumes, images and so on, your app sends received files to inspection via the API. Confirm the verdict before publishing or further processing, and hold malicious or suspicious files.
Files collected in S3
Automatically inspects files placed in S3, such as user upload destinations, file exchange with business partners, and data imported from external systems. No changes to your application are needed.
Investigating suspicious files
Upload attachments reported by employees and similar files from the console, and assess the scope of impact using the verdict reasons, IOCs, MITRE ATT&CK mapping and hunting queries.
IOCs to your monitoring stack
Ingest detected IOCs into your SIEM or threat intelligence platform via STIX / TAXII and use them for matching against internal logs and for monitoring.
Example API integration (web upload feature)
Accept the file
Receive the user's upload and keep it unpublished for now.
Send to the API
Send the file with your API key. Large files are uploaded via a presigned URL.
Get the result
Retrieve the verdict using the SHA-256 returned when the file is accepted.
Act on the verdict
If safe, proceed to publishing or further processing. If malicious or suspicious, hold the file and notify the person in charge.
File-type analysis
Analyze each file format
from a dedicated perspective
Malware hides differently depending on the format. MalScan identifies the format from the file's content, then focuses on the mechanisms most often abused in that format. Files with disguised extensions are analyzed as their true format.
Executables and installers
Looks for signs of packing or encryption, high-entropy sections, suspicious APIs, signs of persistence or ransomware, and execution logic embedded in installers.
Office, RTF and OneNote
Looks for auto-executing macros, downloads from external sources, obfuscation, embedded objects that target known vulnerabilities, and executables attached to documents.
Looks for actions that run on open, embedded JavaScript, launching of external programs, embedded files, and code hidden by encoding.
Scripts, HTML and text
Looks for obfuscation by character-code conversion or concatenation, encoded PowerShell, download-and-execute commands, and techniques that assemble a file inside HTML and make the browser save it.
Archives and shortcuts
Looks at the contents of archives and disk images such as ISO, suspicious launch commands in shortcuts, double extensions, and disguise through icons.
Android, Java and images
Looks for dangerous permissions and accessibility services, runtime code loading, unsigned packages, and executables or archive data appended after image data.
Detection logic
Add up the indicators
and turn risk into a score
MalScan weights the features extracted for each format, adds them up, and calculates a risk score from 0 to 100. It does not reach a conclusion from a single feature; the score rises when multiple indicators overlap. Current verdicts are based on transparent rules, so the features that contributed to the score can be shown directly as the reasons.
Identify the format
Identifies the true format from the leading bytes of the file and sends it to analysis dedicated to that format.
Extract features
Extracts features linked to attacks for each format: structure, entropy, strings, APIs, permissions, embedded objects and more.
Weighted scoring
Each feature is weighted and the file is scored from 0 to 100. Features of the same kind are capped so that a single kind of indicator cannot make the score jump.
4 levels by threshold
80 or higher is malicious, 50 or higher is suspicious, and 30 or higher is low-confidence suspicious. Documents with only one or two weak indicators stay on the safe side.
Archives: worst file wins
Each file inside an archive is scored, and the result of the highest-risk file becomes the overall verdict.
Per-format AI models in development
In addition to the current rule-based verdicts, we are developing dedicated AI models for each file format, to improve our ability to handle unknown malware.
Explainable verdicts
From the basis of the verdict
to the next investigative step
MalScan shows not only “whether it is dangerous” but also why it reached that verdict and what to investigate next. Results can be reviewed file by file in the console, and the dashboard shows the breakdown and trends of verdicts.
4-level verdicts
Malicious, suspicious, low-confidence suspicious and likely benign. Documents with only a single weak indicator stay on the safe side to reduce false positives.
Reasons and IOCs
Lists the detected features as reasons and attaches IOCs such as hash values, entropy, URLs and IP addresses.
MITRE ATT&CK
Automatically maps detections to MITRE ATT&CK techniques and shows which stage of an attack they correspond to.
AI investigation assist
AI organizes IOCs by type and creates queries for hunting traces in Splunk or KQL (optional).
API & threat feed
Connect inspection results
to your own systems
In addition to automatic S3 inspection, you can inspect files directly through the API. Detected IOCs are delivered as a feed, so you can ingest them into your SIEM or threat intelligence platform and use them in your internal monitoring.
Scan API
Send files and retrieve results with an API key. Large files are uploaded via a presigned URL.
STIX 2.1 / TAXII 2.1
IOCs from files judged malicious or suspicious are deduplicated and delivered in STIX 2.1, and can be ingested via TAXII 2.1 from tools such as OpenCTI and MISP.
Isolated per tenant
API keys are bound to a tenant and cannot access other tenants' data. Only the hash of each key is stored.
Managed in the console
Manage AWS account and bucket registration, manual uploads, inspection results, API keys and AI settings in the unified console.
Specifications
Scope and delivery
| Targets |
|
|---|---|
| Deployment |
|
| Supported formats |
|
| Verdict method |
|
| Integrations |
|
| AI analysis (optional) |
|
Please note: Verdicts are based on static analysis and heuristics; MalScan does not perform antivirus signature matching or dynamic execution in a sandbox. Password-protected archives are extracted only when protected with passwords commonly used for analysis samples. Usage fees for AI analysis (Amazon Bedrock or Anthropic) are paid by you.
Getting started
Getting started
Create the role
Create the integration role with CloudFormation and confirm the connection in the console.
Add buckets
Select and add the S3 buckets you want to inspect from the console. Event notifications are configured automatically.
Automatic inspection
From then on, every stored file is inspected automatically and the results appear in the console.
Use the results
Bring inspection results into your SIEM and business systems through the API or the IOC feed.
FAQ
FAQ
Are files judged malicious deleted automatically?
MalScan provides verdicts and results. For quarantine or deletion, retrieve the results via the API and build them into your own workflow.
Can password-protected ZIP files be inspected?
Files protected with passwords commonly used for analysis samples are extracted and their contents inspected. Others cannot be extracted, so the presence of an encrypted file is shown as a reason in the verdict.
Is AI analysis required?
It is optional. Without AI analysis, you still get the verdict, reasons, IOCs and MITRE ATT&CK mapping.
Where are files analyzed?
Files are read from your bucket using the registered role and analyzed in the CyberForces inspection environment (AWS Tokyo Region).
Works well with
MalScan — details and demo requests
Our team will explain deployment options and pricing for your environment.