Frequently Asked
Questions
Our core differences are in both security and usability.
From a security standpoint, Resec takes a stringent Zero Trust prevention approach. Most anti-malware solutions rely on detection of threats via signatures or known and predicted behaviors. While these detection solutions are sometimes effective, they are vulnerable to evasive techniques and false negatives.
From a usability standpoint, Resec processes at scale and 90% faster than most sandboxes. We enable organizations to remove restrictions and facilitate business flows without adding any additional risk.
Content Disarm and Reconstruction (CDR) technology breaks down documents into bits and bytes, and reconstructs files into threat-free replicas that only contain known, safe elements. Resec’s CDR eliminates Zero Day attacks and false negatives. Resec always processes full CDR, while consistently maintaining the file’s native format and full functionality, at scale and in real time.
No. Files are first processed through Resec’s advanced detection engines. This initial step detects known malware and enforces organizational policies. After this critical step, blocked and permitted files are reported to the customer, but not processed by CDR. Following this process, the remaining permitted files will be reconstructed.
Zero Day attacks are unknown threats that cannot always be detected. To fully prevent such attacks, Resec rebuilds files with known, safe elements. This process eliminates any “pockets” in which unknown threats can be hidden, without the need to identify (or detect) the specific threat.
Resec’s platform is used by some of the world’s most sensitive organizations, who pass their core file traffic through Resec with confidence. Since our inception, customers have utilized Resec to successfully process >1 billion files. Resec’s capabilities are best demonstrated via a low-touch, customized Proof of Value.
Since Resec is installed on-premise or in a private cloud, all processing is performed and all data is stored on the customer’s end. Once the system is deployed and installed by the customer, all external access to the system is lost and even Resec has no access to the platform or any of its processed data.
Resec’s advanced detection engines support over 250 file types, and its CDR engine supports over 50 file types. These file types include Emails, MS-Office, OpenOffice, Visio, PDF, HTML, Image, Archive, etc. Additional file-types, including proprietary ones, can be added upon request.
Resec recursively processes all commonly used archive types, including ZIP, RAR, 7zip and tar.gz as well as files embedded within Office documents, PDFs and more.
We offer the following policy options to process active content:
- Block all active content; executable file-types will be blocked. Active content within permitted file types will be stripped without blocking the entire file.
- Pass the files containing active content through Resec’s advanced detection engines only, including Resec’s proprietary macro scanner, and deliver the original file to its destination.
- Pass only the files containing active content through a sandbox and deliver the original file to its destination.
Yes, once the password is provided, Resec successfully processes encrypted files and emails (including multi-layered encryption).
We offer the following policy options for digitally signed documents:
- Block all digitally signed documents
- Pass the digitally signed documents through Resec’s advanced detection engines (sandbox processing is optional), and deliver the original file to its destination
- Allow Resec to fully process the digitally signed documents. The reconstructed digitally signed document will include a reference to the original signed document that can be stored in an external repository, maintained by the customer for as long as desired.
Passing certain files through a sandbox is only optional. We recommend using a sandbox only as an extra measure for outlier cases that cannot be reconstructed (executables, ~1-2% of files).
Resec customers shift most of their file traffic to Resec, drastically improving on every security and usability metric, reducing their sandbox usage, and saving money.
Resec’s advantages over sandboxes are demonstrative:
- Resec provides ultimate security from Zero Day threats.
- Resec is not prone to evasive techniques.
- Resec is at least 90% faster.
- Resec processes encrypted documents and large files.
- Resec is far more scalable and cost effective.
Resec stores the original files in a secured quarantine area, outside of the organization’s network (usually in the DMZ). The organization may elect to store the original files and retain access to them for as long as desired.
Resec supports a configurable file retention policy, allowing the administrator to keep blocked files and emails quarantined for a predetermined period of time or storage limit. IT administrators may perform additional analysis on the blocked files and emails if required.
The system can be installed as an on-premise virtual appliance, a separate VLAN, or as part of the domain network. Resec can also be hosted in the private cloud. As a Zero Trust prevention platform, Resec is always positioned between the organization and the threat. Resec integrates with mail servers, file servers, protocols, and 3rd party solutions while maintaining this Zero Trust approach.
Yes. The platform offers an extensive set of APIs that enables seamless integration with third-party solutions. Resec currently integrates with best-of-breed security products, including leading mail gateways, sandboxes, web gateways, AVs, device controls, and SIEM systems.
8 Cores
16GB RAM
500GB Disk Space
Windows Server 2019 or above
Resec’s licensing model is an annual subscription for each protection vector.
No, you can buy each protection vector separately. The Resec platform will allow you to add or remove vectors without interrupting your business flows.
Resec’s price is derived from the customer’s system processing requirements.
To provide a quote, we simply need to know the following:
- Resec module/s (Email, FTP, API etc.) of interest
- Expected number of users
- Expected traffic at peak (GB/hr)
End Ransomware Today.
Contact us now and learn how Resec’s Zero Trust prevention solution can help secure your organization
Contact Us