A verdict before you finish asking the question
A suspicious attachment, a downloaded binary, a supplier’s deliverable. Server settles it: malicious or not, which family, and how closely related to known threats.
- Detects 0-day variants ahead of 90% of market antivirus solutions
- Names the family and attributes the threat, without signatures
- Identifies packers and unpacks automatically
- MITRE ATT&CK matrix of the techniques identified in the file
- File comparison: what one binary shares with another, and in what proportion
- Malware CTI: the sample linked to threats already known
- PDF report, ready to use for remediation
- Called through the API from your EDR, SIEM or SOAR
Analysis in under one second
SaaS or on-premises

GORILLE SERVER IN THREE SCREENS
1 · The verdict
Every file submitted gets a verdict and a family name. Here LockerGoga, the Danabot/RedLine/DcRat combination, and Akira — three samples settled by static analysis.

2 · How much of the binary is malicious
GORILLE does not stop at « malicious »: it measures how much malicious code the binary contains. Here 7 %, the rest being legitimate code, often borrowed from clean programs.

3 · Related families
The engine places the sample among known families, with a correlation rate and the number of shared code sites. Akira at 100 %, BlackBasta at 87 %, HelloKitty at 20 %.

DEPLOYMENT AND BILLING
SAAS OR ON-PREMISES
GORILLE Server is the only product in the suite available as SaaS. In SaaS, billing is a token-based subscription: one token, one analysis. On-premises, it is an annual licence, with a dynamic analysis option and a private server option.
LET’S TALK ABOUT YOUR NEED
A file to analyse, an incident under way, an estate to sweep: tell us where you stand. You will be put in touch with an engineer, not with a canned form.