FileDNAtm, an advanced cybersecurity solution from CyberQuay Inc., provides comprehensive analysis and neutralizes suspicious and malicious content embedded in data sources, warranting data integrity and security. With a straightforward interface, this solution seamlessly integrates into any layer of a cybersecurity platform, enhancing its capabilities and delivering unmatched protection.
The Five-Stage Processing Pipeline
- FileDNA™ receives the file via the RESTful API or SDK integration. Any supported format is accepted, including nested containers and multi-level archives. The file is queued for structural analysis without being executed at any stage.
- The engine performs deep structural parsing of the entire file. Every embedded object is identified and extracted: macros, scripts, JavaScript layers, executable attachments, annotation objects, image payloads, metadata fields, linked objects, and external references. For archive types, this process recurses through unlimited nesting levels until every embedded object has been identified and mapped.
- Each extracted object is evaluated against the permitted content rules for the container format and the organization’s configured security policy. Proprietary detection algorithms examine structural characteristics, encoding patterns, obfuscation signatures, and behavioral indicators. Machine learning models trained in real-world malicious samples provide an additional analysis layer for identifying sophisticated or novel threats.
- Objects that violate policy are removed or replaced. Binary executable attachments are substituted with safe placeholder content that preserves the structural integrity of the container. Malicious macros, obfuscated scripts, embedded executables, suspicious external links, hidden metadata, and AI-targeted instruction payloads are removed. The file is then reconstructed from the compliant remaining content.
- The sanitized file is returned to the requesting system within seconds, accompanied by a detailed report documenting every action taken, every object removed, and the classification of each detected threat. The report is structured for integration into SIEM platforms, security dashboards, and analyst workflows.

