Malware Prevention
Stop malware, known and unknown.
Cato Malware Prevention delivers a multi-layered approach.
Catch zero-days in a millisecond.
NGAM analyzes file content in real time and delivers a benign, suspicious, or malicious verdict in typically under a millisecond.
Investigate with precision.
Cato Sandbox detonates suspicious files in isolation and produces rich forensic reports.
Malware hides to get in.


Zero-day & polymorphic malware
Novel and shape-shifting malware slips past signature-only engines that only recognize yesterday's known threats.
Threats hidden in encrypted traffic
More than 90% of web traffic is encrypted — without TLS inspection, enterprises are blind to the malware hiding inside it.
Evasion via nested archives
Threat actors bury payloads in nested archives and encrypted files to bypass security engines entirely.
Legacy appliance limits
Fixed appliance resources force trade-offs on how much traffic — and how many files — actually get scanned.
Block known threats.
Detonate the unknown.
Known and unknown malware now hides inside encrypted traffic and evasive files. Cato applies multi-layered, AI-driven prevention and sandboxing at wire speed, inspecting every file — including inside TLS — so threats are stopped before they reach a user.
Inspect every file
Scan every file at wire speed, including inside TLS-encrypted traffic — with no appliance limits on what gets inspected.
Detect with AI + signatures
NGAM, in partnership with SentinelOne, and a continuously updated signature and heuristics database return a verdict in under a millisecond.
Detonate the unknown
Send suspicious files to Cato Sandbox for deep behavioral analysis and forensic reports with IOCs.
Cato Networks Advanced Security Services
Malware Prevention Capabilities
Real-time protection from zero-day malware
Cato's NGAM detects zero-day and polymorphic malware in real time, returning a verdict of benign, suspicious, or malicious.
- ML maps connections across thousands of data points
- Verdict in typically under a millisecond
- Built in partnership with SentinelOne

Always up-to-date protection
Cato scans every file at wire speed against a signature and heuristics database that is continuously updated.
- Replace anti-malware engines of legacy firewalls and UTMs
- No manual infrastructure to manage
- No fixed-appliance resource constraints

Complete protection with TLS inspection
More than 90% of web traffic is encrypted; Cato's SASE cloud performs TLS inspection at scale so NGAM has complete visibility.
- No impact on performance
- Granular, policy-based inspection scope
- No legacy appliances to size and scale

Protection for nested archives and encrypted files
NGAM supports multiple file types and scans multiple levels within nested archive files.
- Hold archive files until confirmed malware-free
- Block encrypted or password-protected files by policy
- Address a common security-bypass technique

Granular policy and simple exception controls
Define allow and block actions based on context such as Internet or WAN, source, application, and more.
- Specific or global exceptions to fit the business
- A stricter posture without losing agility
- Policy changes take effect globally in minutes
Cato Sandbox for evasive threats
Cato Sandbox automatically detonates suspicious or malicious files in a controlled, isolated environment.
- Rich forensic reports with IOCs and attack behavior
- Download reports directly from the CMA
- Accelerate incident response and investigation

Watch how Cato does it
Customers love Cato
Cato gives us secure access with encryption, Web filtering, IPS, next-gen anti-malware, and visibility of what our workers are doing, so that our clients can be confident in the quality of the connection coming into them.
Get a live demo
Secure every interaction across the enterprise, cloud, and AI with the only purpose-built SASE platform.
15–30 minute session with a SASE product expert
Discuss your use cases and how we can help
Live product demonstration where applicable
See Cato in Action
Request received
Thanks, there. A Cato specialist will reach out at to schedule your session.
