Home / Services / MalScan

Malware inspection for files

Inspect uploaded files
the moment they land.

MalScan automatically analyzes files stored in Amazon S3 and determines whether they are suspected malware. It identifies each file's format from its content and sends it to analysis dedicated to that format: executables, Office documents, PDFs, scripts, archives and more. Each verdict comes with reasons and IOCs (indicators of compromise), mapped to MITRE ATT&CK techniques. Results can also be fed into your SIEM or threat intelligence platform via the API or a STIX / TAXII feed.

Challenges

Sound familiar?

Upload features become an entry point

Attachments to contact forms and application pages become a path for bringing malware into your organization.

No basis for the verdict

Being told only that a file is “dangerous” does not let you decide how to respond if you do not know what the problem is.

Building inspection takes effort

Building S3 event notifications, queues and per-format analysis yourself takes a lot of effort.

Features

MalScan key features

01Automatic inspection on S3 upload

Register a bucket and S3 event notifications are configured automatically, so every file placed there is inspected. You can register multiple AWS accounts and buckets.

02Format detection by content

The format is determined from the leading bytes of the file, not the extension, so files with a disguised extension are still analyzed as their true format.

03Per-format analysis

Executables, Office documents, RTF, PDF, scripts, HTML, shortcuts, disk images, OneNote, MSI, Android, Java, images and more are each analyzed from a dedicated perspective.

04Archives inspected inside

Files inside archives are extracted and inspected, and the highest-risk result becomes the overall verdict. Extraction volume is capped to guard against decompression bombs.

054-level verdicts with reasons

Files are classified into 4 levels (malicious, suspicious, low-confidence suspicious, likely benign) with reasons, hash values, entropy and IOCs.

06Mapped to MITRE ATT&CK

Files judged malicious or suspicious are automatically mapped to MITRE ATT&CK techniques based on what was detected. There is no additional charge.

07AI IOC triage and hunting queries

AI organizes IOCs and creates Splunk and KQL hunting queries (optional). It runs on Amazon Bedrock in your AWS account or with your Anthropic API key.

08API and IOC feed

Use an API key to submit files for inspection and retrieve results. Detected IOCs are delivered via STIX 2.1 / TAXII 2.1 for ingestion into a SIEM or threat intelligence platform.

Use cases

Build inspection into
wherever files come in

Files from outside arrive through many paths: web upload features, S3 buckets, attachments sent to employees and more. MalScan offers 3 entry points (automatic S3 inspection, the API and the console), so you can build it into each path.

WEB UPLOAD · API

Upload features in web services

In forms that accept application documents, resumes, images and so on, your app sends received files to inspection via the API. Confirm the verdict before publishing or further processing, and hold malicious or suspicious files.

S3 BUCKET

Files collected in S3

Automatically inspects files placed in S3, such as user upload destinations, file exchange with business partners, and data imported from external systems. No changes to your application are needed.

INVESTIGATION

Investigating suspicious files

Upload attachments reported by employees and similar files from the console, and assess the scope of impact using the verdict reasons, IOCs, MITRE ATT&CK mapping and hunting queries.

SOC · SIEM

IOCs to your monitoring stack

Ingest detected IOCs into your SIEM or threat intelligence platform via STIX / TAXII and use them for matching against internal logs and for monitoring.

Example API integration (web upload feature)

  1. Accept the file

    Receive the user's upload and keep it unpublished for now.

  2. Send to the API

    Send the file with your API key. Large files are uploaded via a presigned URL.

  3. Get the result

    Retrieve the verdict using the SHA-256 returned when the file is accepted.

  4. Act on the verdict

    If safe, proceed to publishing or further processing. If malicious or suspicious, hold the file and notify the person in charge.

File-type analysis

Analyze each file format
from a dedicated perspective

Malware hides differently depending on the format. MalScan identifies the format from the file's content, then focuses on the mechanisms most often abused in that format. Files with disguised extensions are analyzed as their true format.

PE / ELF / MSI

Executables and installers

Looks for signs of packing or encryption, high-entropy sections, suspicious APIs, signs of persistence or ransomware, and execution logic embedded in installers.

DOCUMENTS

Office, RTF and OneNote

Looks for auto-executing macros, downloads from external sources, obfuscation, embedded objects that target known vulnerabilities, and executables attached to documents.

PDF

PDF

Looks for actions that run on open, embedded JavaScript, launching of external programs, embedded files, and code hidden by encoding.

SCRIPTS

Scripts, HTML and text

Looks for obfuscation by character-code conversion or concatenation, encoded PowerShell, download-and-execute commands, and techniques that assemble a file inside HTML and make the browser save it.

CONTAINERS

Archives and shortcuts

Looks at the contents of archives and disk images such as ISO, suspicious launch commands in shortcuts, double extensions, and disguise through icons.

APPS / IMAGES

Android, Java and images

Looks for dangerous permissions and accessibility services, runtime code loading, unsigned packages, and executables or archive data appended after image data.

Detection logic

Add up the indicators
and turn risk into a score

MalScan weights the features extracted for each format, adds them up, and calculates a risk score from 0 to 100. It does not reach a conclusion from a single feature; the score rises when multiple indicators overlap. Current verdicts are based on transparent rules, so the features that contributed to the score can be shown directly as the reasons.

1 · IDENTIFY

Identify the format

Identifies the true format from the leading bytes of the file and sends it to analysis dedicated to that format.

2 · EXTRACT

Extract features

Extracts features linked to attacks for each format: structure, entropy, strings, APIs, permissions, embedded objects and more.

3 · SCORE

Weighted scoring

Each feature is weighted and the file is scored from 0 to 100. Features of the same kind are capped so that a single kind of indicator cannot make the score jump.

4 · CLASSIFY

4 levels by threshold

80 or higher is malicious, 50 or higher is suspicious, and 30 or higher is low-confidence suspicious. Documents with only one or two weak indicators stay on the safe side.

ARCHIVES

Archives: worst file wins

Each file inside an archive is scored, and the result of the highest-risk file becomes the overall verdict.

IN DEVELOPMENT

Per-format AI models in development

In addition to the current rule-based verdicts, we are developing dedicated AI models for each file format, to improve our ability to handle unknown malware.

Explainable verdicts

From the basis of the verdict
to the next investigative step

MalScan shows not only “whether it is dangerous” but also why it reached that verdict and what to investigate next. Results can be reviewed file by file in the console, and the dashboard shows the breakdown and trends of verdicts.

VERDICT

4-level verdicts

Malicious, suspicious, low-confidence suspicious and likely benign. Documents with only a single weak indicator stay on the safe side to reduce false positives.

EVIDENCE

Reasons and IOCs

Lists the detected features as reasons and attaches IOCs such as hash values, entropy, URLs and IP addresses.

MITRE

MITRE ATT&CK

Automatically maps detections to MITRE ATT&CK techniques and shows which stage of an attack they correspond to.

AI ASSIST

AI investigation assist

AI organizes IOCs by type and creates queries for hunting traces in Splunk or KQL (optional).

API & threat feed

Connect inspection results
to your own systems

In addition to automatic S3 inspection, you can inspect files directly through the API. Detected IOCs are delivered as a feed, so you can ingest them into your SIEM or threat intelligence platform and use them in your internal monitoring.

SCAN API

Scan API

Send files and retrieve results with an API key. Large files are uploaded via a presigned URL.

THREAT FEED

STIX 2.1 / TAXII 2.1

IOCs from files judged malicious or suspicious are deduplicated and delivered in STIX 2.1, and can be ingested via TAXII 2.1 from tools such as OpenCTI and MISP.

ISOLATION

Isolated per tenant

API keys are bound to a tenant and cannot access other tenants' data. Only the hash of each key is stored.

CONSOLE

Managed in the console

Manage AWS account and bucket registration, manual uploads, inspection results, API keys and AI settings in the unified console.

Specifications

Scope and delivery

Targets
  • Files stored in Amazon S3 buckets
  • Manual uploads from the console
  • Inspection requests via the API
Deployment
  • Create a role in each AWS account with CloudFormation
  • Add buckets from the console (event notifications are configured automatically)
Supported formats
  • Windows / Linux executables, MSI
  • Office documents (including macros), RTF, OneNote, PDF
  • Scripts, HTML, text
  • Shortcuts, disk images such as ISO, archives
  • Android (APK / AAB), Java (JAR), images
Verdict method
  • Per-format static analysis and heuristics
  • 4 levels: malicious, suspicious, low-confidence suspicious, likely benign
Integrations
  • Scan API (API key authentication)
  • IOC feed (JSON, STIX 2.1, TAXII 2.1)
AI analysis (optional)
  • Runs on Amazon Bedrock in your AWS account or with your Anthropic API key

Please note: Verdicts are based on static analysis and heuristics; MalScan does not perform antivirus signature matching or dynamic execution in a sandbox. Password-protected archives are extracted only when protected with passwords commonly used for analysis samples. Usage fees for AI analysis (Amazon Bedrock or Anthropic) are paid by you.

Getting started

Getting started

  1. Create the role

    Create the integration role with CloudFormation and confirm the connection in the console.

  2. Add buckets

    Select and add the S3 buckets you want to inspect from the console. Event notifications are configured automatically.

  3. Automatic inspection

    From then on, every stored file is inspected automatically and the results appear in the console.

  4. Use the results

    Bring inspection results into your SIEM and business systems through the API or the IOC feed.

FAQ

FAQ

Are files judged malicious deleted automatically?

MalScan provides verdicts and results. For quarantine or deletion, retrieve the results via the API and build them into your own workflow.

Can password-protected ZIP files be inspected?

Files protected with passwords commonly used for analysis samples are extracted and their contents inspected. Others cannot be extracted, so the presence of an encrypted file is shown as a reason in the verdict.

Is AI analysis required?

It is optional. Without AI analysis, you still get the verdict, reasons, IOCs and MITRE ATT&CK mapping.

Where are files analyzed?

Files are read from your bucket using the registered role and analyzed in the CyberForces inspection environment (AWS Tokyo Region).

Works well with

MalScan — details and demo requests

Our team will explain deployment options and pricing for your environment.