Our GORILLE solutions are designed to reveal malware hidden in your executable files before it’s too late.
GORILLE
Server
protects you from targeted attacks
GORILLE
Expert
disassembles and characterises executables
GORILLE
Patrol
flushes out dormant threats

GORILLE
On-Demand
has your files analysed by our experts
WHAT GORILLE DOES, IN FIGURES

< 1 s
to analyse a file

95 – 100 %
detection rate on known malwares

90 %
of market antivirus solutions outpaced on variants

< 5 %
false positives

Up to 80 %
MTTR reduction

Millions
of malwares in the knowledge base
LOCKBIT 2.0: FIFTEEN DAYS AHEAD
In June 2021, GORILLE identified LockBit 2.0 fifteen days before most market antivirus solutions detected it. A year later, in LockBit 3.0, the engine found traces of BlackMatter code: the lineage between two families, which signatures alone do not show.
WHICH GORILLE SOLUTION IS FOR YOU?
Four products, four moments: clearing doubt on a file, understanding a piece of code, hunting what is already sleeping in your network, and having a file analysed when you have no team to do it.
| GORILLE Server | GORILLE Expert | GORILLE Patrol | GORILLE On-Demand | |
|---|---|---|---|---|
| The question | Is this file malicious? | What is this binary made of, and who should it be attributed to? | Am I already compromised? | Who can I entrust this file to? |
| Who it is for | SOC, CERT, IT teams, vendors embedding detection | Malware analysts, reverse engineers | CISOs, IT teams, MSSPs | SMEs, local authorities, organisations with no analysis team |
| What it does | Verdict and characterisation in under a second | Disassembly and morphological analysis of executables | Scanning campaigns across your estate | Analysis by our experts, backed by the GORILLE engine |
| What you get | Malware family, MITRE ATT&CK matrix, file comparison, malware CTI, PDF report | Code characterisation, family attribution, 3D representation of the threat | Inventory of dormant threats, before detonation | A readable report within 48 h: danger level, explanation of the results, remediation steps |
| Deployment | SaaS or on-premises | On-premises | On-premises | None — online service |
| Billing | Token-based subscription (SaaS) or annual licence (on-premises) | Annual licence | Per campaign, based on the number of endpoints scanned | Per analysis, one file at a time |
| Integration | REST API — EDR, XDR, SIEM, SOAR | Analyst workstation | Agent and console | Online file upload |
| Files and environments | All file types — executables, documents and scripts — on Windows, Linux, Android and macOS | |||
THE FOUR SOLUTIONS
Each product answers a different moment. Open the one that matches yours.
GORILLE Server
Is this file malicious?
Verdict and characterisation in under a second, as SaaS or inside your own infrastructure.
GORILLE Expert
What is this binary made of?
The reverse engineering tool: disassembles, compares, characterises, attributes.
GORILLE Patrol
Am I already compromised?
Scanning campaigns across your estate, to flush out dormant threats.
GORILLE On-Demand
Who can I entrust this file to?
Your files analysed by our experts, with a readable report within 48 hours.
DEPLOY YOUR WAY, PAY FOR WHAT YOU USE
Two ways to install GORILLE, three ways to pay for it. SaaS is available for GORILLE Server only; GORILLE Expert and GORILLE Patrol are installed exclusively inside your own infrastructure.
SAAS · TOKEN-BASED SUBSCRIPTION · GORILLE SERVER
Analysis with no infrastructure
Applies to GORILLE Server only.
GORILLE Server analyses your files on our platform. No server to provision, no updates to manage: you open an account, you call the API, you get a verdict.
- Live immediately, with no infrastructure project
- One token, one analysis: you pay for the files you analyse
- Volume adjusts to your actual activity
- Private server option to isolate your analyses
The right choice if you want to start fast, or if your analysis volume is irregular. Available for GORILLE Server only.
ON-PREMISES · THE WHOLE SUITE
Your files never leave
Applies to all three products: GORILLE Server, GORILLE Expert and GORILLE Patrol.
GORILLE is installed inside your own infrastructure. No sample ever leaves it — the entry condition for sensitive environments, critical infrastructure operators and any analysis under regulatory constraint.
- Full sovereignty: samples stay with you
- Annual licence for GORILLE Server and GORILLE Expert: a budget known up front
- GORILLE Patrol is billed per campaign, based on the number of endpoints scanned
- Direct integration with your SIEM and SOAR through the API
- Dynamic analysis option
The right choice if your data cannot leave, or if you analyse continuously. It is the only deployment mode for GORILLE Expert and GORILLE Patrol.
THE GORILLE ENGINE IS ALSO AT AIRBUS
Cyber-Detect and Airbus combine their expertise to push the boundaries of threat detection. This partnership enables advanced detection, including against zero-day attacks, as well as fine-grained malware classification. Discover the Gorille characterization engine, now integrated into Orion Malware by Airbus.
LET’S TALK ABOUT YOUR NEED
A file to analyse, an incident under way, an estate to sweep: tell us where you stand. You will be put in touch with an engineer, not with a canned form.