Nothing harmful leaves. Everything useful stays.

Content Disarm and Reconstruction returns a clean copy of the document, not a verdict about the old one.

Lives inside HookMesh

Three stages. Milliseconds.

The file goes in one side and a clean copy comes out the other. There is no verdict in between, because none is needed.

A document breaks into blocks, the red blocks hidden inside drop out, and the same document is rebuilt from the rest.
  1. Sanitize

    The file is taken apart into its parts. Everything that can execute, macros, scripts, embedded objects, is removed.

  2. Reconstruct

    The document is rebuilt from the safe parts alone. Text, layout and images survive. It takes milliseconds.

  3. Deliver

    A usable copy reaches the user. The original never does.

50+ file types rebuilt

Zero trust, applied to files: every one is treated as untrusted and rebuilt, so no detection decision is ever needed.

Sanitized files do not raise alerts. Fewer alerts mean a lighter SOC queue, and analysts spend their time on what is left.

Fewer alerts, inside HookMesh
HookMesh

CDR ships inside HookMesh, which routes every file through it and the tools you already run.

See HookMesh

Questions we get asked

What is CDR in cyber security?

Content Disarm and Reconstruction. Instead of deciding whether a file is malicious, CDR takes the file apart, removes everything that could execute, such as macros, scripts and embedded objects, and rebuilds a clean copy from the safe parts. The user gets a usable document; the original never reaches them.

How is CDR different from a sandbox?

A sandbox runs the file and returns a verdict, which takes minutes and can be evaded. CDR does not judge the file at all; it rebuilds it in milliseconds, so unknown and zero-day content is neutralised without being recognised first. Malwation uses both: CDR at the gateway, the sandbox for what needs a verdict.

How is CDR different from antivirus or EDR?

Antivirus and EDR detect: they need a signature, a rule or a behaviour to match, and they miss what they have not seen. CDR prevents: every file is treated as untrusted and rebuilt, so nothing has to be detected. Sanitized files also raise no alerts, which lightens the SOC queue.

Which file types does CDR handle?

More than 50, the everyday document formats first: Office files and PDF among them. Text, layout and images survive the rebuild; macros, scripts and embedded objects do not. The copy that comes out opens like the original and carries none of its active content.

Where does CDR sit in the network?

At the points where files enter a company: inline at the mail gateway, at the entry to file shares, and behind web upload forms used by support, HR and finance. HookMesh routes each source through CDR and, where you choose, through static analysis and the sandbox as well.

Send us a document. Get it back clean.

We will run a real file of yours through CDR and show you the copy that comes out the other side.

Get a demo