Assemblyline

Assemblyline

Automated file triage and malware analysis

Description

Security teams receive piles of suspicious attachments that cannot all be analyzed by hand. Assemblyline 4, open sourced by the Canadian Centre for Cyber Security, is an automated malware analysis framework for triaging files at scale.

It runs on Kubernetes and Docker, scaling from small appliances to large deployments for incident response and threat research.

Features



Triage:File risk at scale.

Detection:Multiple engines.

Scalable:Kubernetes.

Incident response:Investigation support.