Check before and alongside the rebuild
Second opinions where the rebuild needs help: new threats, programs, macros you keep, signed installers, and text bound for AI models.
AI-powered threat prediction
Get an early warning about risky files, even threats no signature has seen.
Some threats are too new for any scanner to know. Glasswall Halo uses machine learning to score each file's risk from its internal structure. It needs no signatures, sandbox or internet connection. It covers PDF, DOCX and XLSX files.
- Reads structure, not signaturesThe score comes from how the file is built, so a threat nobody has seen before can still score high.
- Leaves the file aloneIt adds a risk score without changing the file.
- Works offlineNeeds no internet connection, so it suits air-gapped and disconnected sites.
- PDF, Word and ExcelCoverage today is PDF documents, Word documents (DOCX) and Excel workbooks (XLSX).
- Connects via
- Glasswall Halo
Prompt injection detection
Spot prompt injection in text before your application sends it to an AI model.
Text sent to a large language model (LLM) can carry planted instructions that change what it does. Glasswall Halo checks the text first and returns one of three verdicts. English only, up to 512 tokens per request, with a separate Pulsar licence.
- Three clear verdictsNo Threat Detected, Suspicious or Malicious, so your application can decide whether to send the text on.
- Text, not filesIt checks the text your application is about to send to the model. It does not check files.
- Know the limitsEnglish only in this first release. Up to 512 tokens per request, the units AI models count text in. Longer text is rejected.
- Runs in your own HaloRuns inside your Glasswall Halo deployment and is called through one web API request. It needs a separate Pulsar licence.
- Connects via
- Glasswall Halo REST API
File reputation
Check each file against ReversingLabs threat intelligence, including files Halo cannot rebuild.
Some files, such as programs, are outside what Glasswall Halo can rebuild. File reputation, built into Halo, looks up each file's fingerprint with ReversingLabs in real time and returns a verdict. It needs your ReversingLabs account and a live internet connection.
- A clear verdictEach file comes back UNKNOWN, KNOWN, SUSPICIOUS or MALICIOUS, with a threat name and a threat level.
- Covers what the rebuild cannotYour policy can act on programs and other file types that Glasswall Halo does not rebuild.
- Results where you already lookVerdicts appear in Halo's response and its analysis report, so existing integrations can read them.
- Needs a connectionEvery lookup goes to ReversingLabs over the internet. Fully air-gapped sites run without it, and the rebuild never depends on it.
- Connects via
- Glasswall Halo, with a live ReversingLabs connection
Multi-AV scanning
Pass a file only when every anti-virus engine says it is clean.
One anti-virus engine can miss what another catches. Choose a curated pack of engines from different vendors, or bring the scanners you already run. Each file goes to every engine at once and passes only when all report it clean.
- Every engine must agreeEngines scan in parallel. A file passes only when each one reports it clean, and each verdict is recorded separately.
- Engines from across the marketCurated packs combine engines from different vendors, so one engine's blind spot is covered by another.
- Or bring your ownConnect any scanner you already run that supports ICAP (Internet Content Adaptation Protocol).
- Out-of-date engines are not trustedAn engine with old or unknown signature updates is refused by default: a warning at 7 days, a refusal at 30.
- Updates for air-gapped sitesSignature updates arrive as signed bundles, checked in full before anything in them is trusted.
- Connects via
- Curated AV engine packs, or bring your own
Macro analysis
Know what a macro would do before anyone enables it, without running it.
Some organisations must keep trusted macros in their documents, so they cannot simply remove them. Macro analysis examines the macros your Glasswall Halo policy keeps and gives a verdict with its reasons. Documents are never opened in Office, and the macros are never actually run.
- Four verdictsBlock, Flag, Allow or Clean, each with the findings that led to it.
- The formats that carry codeWord and Excel macros, including older Excel 4.0 macros, older Office files, PDF scripts and HTML scripts.
- Behaviour, safely simulatedA simulator traces what the macro would do and draws it as a diagram. No real program, network or file is touched.
- Findings your SOC can useFindings are tagged with MITRE ATT&CK, the common catalogue of attacker techniques.
- Indicators to investigateWeb addresses, IP addresses, file paths and decoded hidden text are pulled out for your threat-intelligence team.
- Connects via
- Glasswall Halo, alongside the rebuild
Signed software verification
Let genuine signed installers through unchanged, and block anything that fails the checks.
Signed installers are trusted because of who signed them, not rebuilt. This checks the publisher's digital signature and approved lists of file fingerprints. Any deny blocks the file. A fingerprint on no list counts as unknown, never as approved. Every decision is recorded.
- Checks the publisher's signatureVerifies Microsoft Authenticode signatures on Windows programs and packages (EXE, DLL, MSI, CAB, MSU, APPX, MSIX). It can also require the one publisher you expect.
- Approved fingerprint listsLists of approved file fingerprints load only if their own signature, certificate and cryptography pass the checks.
- Any deny winsA deny on any list blocks the file. A file on no list is unknown, never approved.
- Exceptions with a name attachedYour own additions to the approved list need a recorded approval naming the approver, kept in a tamper-evident log.
- Connects via
- Part of the Halo file checks