Secure Malware Analytics
Sandbox malware analysis and threat intelligence in one platform.
Cisco Secure Malware Analytics (formerly Threat Grid) combines advanced sandboxing with context-rich threat intelligence so security teams can analyse suspicious files and understand the threats that matter. Available as a standalone appliance, cloud subscription, or integrated into the Cisco security stack, it delivers timely, actionable intelligence to identify malware and mitigate its damage. Faltrox operates it as the malware-analysis layer of detection and response.
Overview
What Secure Malware Analytics is
Organisations face a flood of common and advanced malware, and few teams have time to investigate every attack, let alone prioritise the most dangerous. Cisco Secure Malware Analytics solves that by pairing a large static and dynamic malware-analysis engine (sandboxing) with context-rich threat intelligence, so a suspicious file is not just flagged but understood.
It detonates and analyses files in a controlled environment, then enriches the results with intelligence to produce timely, actionable output — identifying malware, its behaviour, and how to mitigate it. It deploys as a standalone appliance, a cloud subscription, or an integrated part of the Cisco security technologies (and GRC platforms), transparently improving detection across the stack and speeding investigation and response. Faltrox operates it, integrates it with your detection tools, and applies its output to investigation and response.
Coverage
What it protects
The platforms, threats, and surfaces this product is built to defend.
Suspicious Files
Static and dynamic sandbox analysis detonates and dissects suspicious files.
Common & Advanced Malware
Covers the full range from commodity malware to advanced, evasive threats.
Threat Intelligence
Enriches analysis with context-rich intelligence to prioritise the dangerous threats.
Cisco Security Stack
Integrates transparently across existing Cisco security technologies for better detection.
GRC Platforms
Integrates with governance, risk, and compliance platforms for broader workflow.
Deployment Flexibility
Standalone appliance, cloud subscription, or integrated into the Cisco stack.
How it works
The mechanism
How the product moves from signal to protected state, step by step.
- 01
Submit
Suspicious files are submitted from your security tools, manually, or automatically for analysis.
- 02
Detonate
A large static and dynamic analysis engine detonates the file in a controlled environment to observe its behaviour.
- 03
Enrich
Results are enriched with context-rich threat intelligence to identify the malware and gauge its danger.
- 04
Prioritise
Actionable output helps teams prioritise the most dangerous threats and understand how to mitigate them.
- 05
Operate
Faltrox integrates it with your detection stack and applies its output to investigation and response.
Capabilities
Key capabilities
Advanced Sandboxing
A large static and dynamic malware-analysis engine detonates and dissects suspicious files.
Context-Rich Intelligence
Enriches every analysis with threat intelligence to identify malware and its likely impact.
Actionable Output
Produces timely, actionable intelligence to prioritise and mitigate the most dangerous threats.
Transparent Integration
Integrates across existing Cisco security solutions to improve detection without added workflow.
Flexible Deployment
Runs as a standalone appliance, a cloud subscription, or an integrated part of the Cisco stack.
Faster Investigation
Speeds investigation and response by turning raw files into understood threats.
GRC Integration
Integrates with governance, risk, and compliance platforms for broader security workflow.
Team Effectiveness
Increases the effectiveness of security and response teams by focusing effort on real danger.
Works with
Part of the platform
Cisco products this pairs with, and the Faltrox services that operate it.
Delivery
You buy the outcome, not the console
Managed by Faltrox
Faltrox licenses, deploys, and tunes Cisco Secure Malware Analytics for your environment, then runs it as part of a managed service, so you get the protection without staffing another security console.
FAQ
Common questions
01What does it actually do with a file?
It detonates the file in a controlled sandbox using a large static and dynamic analysis engine, observes its behaviour, and enriches the results with threat intelligence — so you get a full picture of what the file is, what it does, and how dangerous it is, rather than just a verdict.
02How is it deployed?
Flexibly — as a standalone on-site appliance, a cloud-based subscription, or as an integrated part of your existing Cisco security technologies. Faltrox scopes the model to your data-residency and integration needs.
03Does it improve our other security tools?
Yes — it integrates transparently across the Cisco security stack, so its malware analysis and intelligence improve detection in your other tools rather than sitting as an isolated capability.
04How does it help a stretched team?
By turning a flood of files into prioritised, understood threats. It gives context-rich, actionable intelligence so teams can focus on the most dangerous malware first and investigate and respond faster, rather than trying to examine every attack.
05How does Faltrox operate it?
We deploy it, integrate it with your endpoint, email, and network detection tools, and apply its analysis and intelligence to the investigations and response we run — using it as the malware-analysis engine behind the SOC services we provide.
Start an engagement
Secure what’s next.
Speak with the engineering team to define scope, walk through the methodology, and decide whether Faltrox is the right team to test and run your environment.
Contact us