GORILLE SUITE

Our GORILLE solutions are designed to reveal malware hidden in your executable files before it’s too late.

WHAT GORILLE DOES, IN FIGURES

Stopwatch

< 1 s

to analyse a file

Target

95 – 100 %

detection rate on known malwares

Double chevron

90 %

of market antivirus solutions outpaced on variants

Funnel

< 5 %

false positives

Clock and downward arrow

Up to 80 %

MTTR reduction

Database

Millions

of malwares in the knowledge base

LOCKBIT 2.0: FIFTEEN DAYS AHEAD

In June 2021, GORILLE identified LockBit 2.0 fifteen days before most market antivirus solutions detected it. A year later, in LockBit 3.0, the engine found traces of BlackMatter code: the lineage between two families, which signatures alone do not show.

WHICH GORILLE SOLUTION IS FOR YOU?

Four products, four moments: clearing doubt on a file, understanding a piece of code, hunting what is already sleeping in your network, and having a file analysed when you have no team to do it.

GORILLE ServerGORILLE ExpertGORILLE PatrolGORILLE On-Demand
The questionIs this file malicious?What is this binary made of, and who should it be attributed to?Am I already compromised?Who can I entrust this file to?
Who it is forSOC, CERT, IT teams, vendors embedding detectionMalware analysts, reverse engineersCISOs, IT teams, MSSPsSMEs, local authorities, organisations with no analysis team
What it doesVerdict and characterisation in under a secondDisassembly and morphological analysis of executablesScanning campaigns across your estateAnalysis by our experts, backed by the GORILLE engine
What you getMalware family, MITRE ATT&CK matrix, file comparison, malware CTI, PDF reportCode characterisation, family attribution, 3D representation of the threatInventory of dormant threats, before detonationA readable report within 48 h: danger level, explanation of the results, remediation steps
DeploymentSaaS or on-premisesOn-premisesOn-premisesNone — online service
BillingToken-based subscription (SaaS) or annual licence (on-premises)Annual licencePer campaign, based on the number of endpoints scannedPer analysis, one file at a time
IntegrationREST API — EDR, XDR, SIEM, SOARAnalyst workstationAgent and consoleOnline file upload
Files and environmentsAll file types — executables, documents and scripts — on Windows, Linux, Android and macOS

THE FOUR SOLUTIONS

Each product answers a different moment. Open the one that matches yours.

GORILLE Server

Is this file malicious?

Verdict and characterisation in under a second, as SaaS or inside your own infrastructure.

GORILLE Expert

What is this binary made of?

The reverse engineering tool: disassembles, compares, characterises, attributes.

GORILLE Patrol

Am I already compromised?

Scanning campaigns across your estate, to flush out dormant threats.

GORILLE On-Demand

Who can I entrust this file to?

Your files analysed by our experts, with a readable report within 48 hours.

DEPLOY YOUR WAY, PAY FOR WHAT YOU USE

Two ways to install GORILLE, three ways to pay for it. SaaS is available for GORILLE Server only; GORILLE Expert and GORILLE Patrol are installed exclusively inside your own infrastructure.

SAAS · TOKEN-BASED SUBSCRIPTION · GORILLE SERVER

Analysis with no infrastructure

Applies to GORILLE Server only.

GORILLE Server analyses your files on our platform. No server to provision, no updates to manage: you open an account, you call the API, you get a verdict.

  • Live immediately, with no infrastructure project
  • One token, one analysis: you pay for the files you analyse
  • Volume adjusts to your actual activity
  • Private server option to isolate your analyses

The right choice if you want to start fast, or if your analysis volume is irregular. Available for GORILLE Server only.

ON-PREMISES · THE WHOLE SUITE

Your files never leave

Applies to all three products: GORILLE Server, GORILLE Expert and GORILLE Patrol.

GORILLE is installed inside your own infrastructure. No sample ever leaves it — the entry condition for sensitive environments, critical infrastructure operators and any analysis under regulatory constraint.

  • Full sovereignty: samples stay with you
  • Annual licence for GORILLE Server and GORILLE Expert: a budget known up front
  • GORILLE Patrol is billed per campaign, based on the number of endpoints scanned
  • Direct integration with your SIEM and SOAR through the API
  • Dynamic analysis option

The right choice if your data cannot leave, or if you analyse continuously. It is the only deployment mode for GORILLE Expert and GORILLE Patrol.

THE GORILLE ENGINE IS ALSO AT AIRBUS

Cyber-Detect and Airbus combine their expertise to push the boundaries of threat detection. This partnership enables advanced detection, including against zero-day attacks, as well as fine-grained malware classification. Discover the Gorille characterization engine, now integrated into Orion Malware by Airbus.

LET’S TALK ABOUT YOUR NEED

A file to analyse, an incident under way, an estate to sweep: tell us where you stand. You will be put in touch with an engineer, not with a canned form.