MonPulse Module · File Threat Detection — In Development (MVP)

FilePhantom

Every file your organisation receives — uploaded by a user, arriving by e-mail, pulled from an integration — is a potential entry point for an attacker. FilePhantom intercepts the file at the moment of ingest, analyses its true nature and stops threats before they reach your systems or your users.

MonPulse moduleMVP · in developmentAPI integrationZero-trust file inspection

Why it exists

Whatever the extension says, a file is untrusted until proven safe.

Traditional antivirus looks for known signatures; a payload that is unsigned, packed or disguised passes straight through. Yet a significant share of attacks start exactly there: a document that looks like an invoice, an executable with an image extension, a polyglot file with a second format embedded inside it.

FilePhantom is MonPulse’s dedicated file threat detection module. It examines every incoming file — whatever its extension or apparent type — for malicious intent. By running content-aware type validation, entropy analysis and signature matching together, it catches hidden, disguised or novel threats the moment they arrive.

  • TypeGuardContent-aware type validation
  • EntropyScanEntropy and obfuscation detection
  • RuleMatchYARA-based signature matching
  • QuarantineOpsInstant quarantine and policy enforcement
  • PolicyEngineDecisions by file type and context
  • AuditTrailAuditable decision and outcome record

FilePhantom is in development (MVP). Module names, scope and performance figures may change between releases; contact us about pilot studies and early access.

Four layers of inspection

What it does

Content-Aware Type Detection

Inspects file content directly — not just extensions — detecting disguised executables, polyglot files and type mismatches before they reach your environment.

Entropy and Obfuscation Analysis

Measures randomness and structural anomalies in files to surface packed, encrypted or obfuscated payloads that evade signature-only tools.

YARA Signature Matching

Applies community and custom YARA rules to identify known malware families, exploit documents and suspicious code patterns.

Automatic Quarantine and Policy Engine

Instantly quarantines suspicious files, notifies security teams and enforces policy-driven block or release decisions without manual intervention.

Zero-Trust File Inspection

Every file is treated as untrusted until proven safe. FilePhantom examines content structure, embedded objects and metadata — it never assumes a file is benign based on its extension or source.

Policy-Driven Decision Engine

Define custom policies for each file type, risk level and business context. FilePhantom enforces your rules automatically — blocking, flagging or forwarding files to suit your organisation’s specific requirements.

Real-Time Quarantine Management

Suspicious files are isolated instantly in a secure quarantine. Analysts can review, release or permanently delete quarantined files through a clear, auditable workflow — so no threat is left unaddressed.

Auditable Decision Record

For every file, which rule fired and why, who made the decision and what became of the file are all recorded; the decision chain can be presented at audit.

A

Where it fits

  • User file upload endpoints on websites and portals
  • E-mail attachments and shared mailboxes
  • Document flows arriving through integrations and APIs
  • CVs, invoices and contracts uploaded into EDMS, CRM and HR systems
  • File exchange with suppliers and partners (SFTP, shared folders)
  • Document upload steps in public services open to citizens
B

Deployment and integration

  • Enabled as a module within MonPulse
  • Inline placement in an existing upload flow through the REST API
  • Integration with e-mail gateways and file sharing systems
  • Alert forwarding to SIEM, ticketing and notification channels
  • Definition of organisation-specific YARA rules and policy sets
  • On-premise or cloud deployment options

Inspection pipeline

  • TypeGuard
    Content-aware type validation
  • EntropyScan
    Entropy and obfuscation detection
  • RuleMatch
    YARA-based signature matching
  • QuarantineOps
    Instant quarantine and policy enforcement
  • PolicyEngine
    Decisions by file type and context
  • AuditTrail
    Auditable decision and outcome record

Request a demo

We can run a short evaluation in your own environment.

Request a demo

Get started

Let us talk about your project.

The first meeting is a discovery session, not a sales pitch. You are also welcome to evaluate our capability directly through a short pilot or proof of concept (PoC) in your own environment.

Fill in the enquiry form

WhatsApp