# Defense Against Zero-Days and AI-Assisted Malware, A Deep CDR™ Technology Test by AV-Comparatives

> Source: <https://www.opswat.com/blog/defense-against-zero-days-and-ai-assisted-malware-a-deep-cdr-test-by-av-comparatives>
> Published: 2026-09-15 01:00:00+00:00

Detection tools have operated on a simple premise: identify the bad file before it does harm. That premise breaks down the moment a threat has never been seen before. A zero-day exploit, a novel obfuscation technique, or malicious code generated by an AI tool has no signature to match, and no established behavioral pattern to flag.

AV-Comparatives is a respected authority in evaluating detection engines rigorously and reporting the gaps honestly. This test covers AV-Comparatives' research on most recent exploitation techniques across the most common file types and scenarios and how OPSWAT’s Deep CDR™ Technology holds up to these threats.

## How AV-Comparatives Tested Deep CDR™ Technology

AV-Comparatives, a respected independent authority in enterprise security software testing, evaluated Deep CDR™ Technology as implemented in MetaDefender™ Core.

Rather than relying on abstract file samples, it built its test cases around the attack scenarios enterprises typically encounter.

Each test case was judged on two fronts at once: whether the threat was completely disarmed, and whether the resulting file retained its structure, formatting, and usability. This separates a lab-grade sanitization test from a simple detection checklist.

## The Results, in Brief

Every scenario category was fully sanitized under the tested workflow configuration, including the techniques we walk through below: embedded object exploits, image steganography, obfuscated content in QR codes, and active content in SVG files, alongside macro-based attacks and archive-based attacks.

Notably, this also included test cases built specifically around AI-assisted malicious content: files containing AI-generated obfuscation, scripts, and structurally deceptive constructs. These were processed through the same sanitization mechanisms as conventionally crafted attacks, with no difference in outcome based on how the malicious content was created.

On the fidelity side, reconstructed files retained their layout, formatting, images, tables, formulas, comments, and navigation elements, with removed risk content such as macros and embedded objects, exactly where the configured policy intended it to act.

## Deep CDR™ Technology in Action: How the Sanitization Actually Works

The scenario categories in the AV-Comparatives test map closely to recent documented attacks and techniques. The following examples illustrate what "100% sanitization" looks like at the file level.

### Embedded Objects in RTF (Zero-day RCE Mitigation)

[CVE-2025-21298](https://www.opswat.com/blog/analyzing-cve-2025-21298-how-opswat-metadefender-core-protects-against-zero-day-attacks), a zero-click remote code execution vulnerability in the Windows OLE library, could be triggered simply by previewing a malicious RTF file in Outlook without any click. 

To tackle this, enabling the "Remove Embedded Object" policy for RTF is enough in the settings of Deep CDR™ Technology.

Deep CDR™ Technology identifies the embedded OLE object as a disallowed node and removes it during reconstruction, neutralizing the exploit path regardless of whether the specific vulnerability had ever been cataloged.

### Pixel-level Steganography in Images

Image-based steganography [hides payloads at the bit or pixel level](https://www.opswat.com/blog/how-base64-encoding-opens-the-door-for-malware), a technique that is nearly invisible to conventional anti-malware scanning. 

Using free [steganography](https://www.opswat.com/blog/create-and-prevent-steganography-in-five-minutes) programs such as 1-2 Steganography, OpenStego, and QuickStego, attackers can create malware within a few minutes and couple lines of code. 

Deep CDR™ Technology addresses this by stripping structured metadata that can carry hidden payloads, then working at the pixel level itself: removing unused data that could hold a partial payload, introducing controlled noise to disrupt any embedded execution logic, and optimizing bitmap compression to eliminate the space where a payload would otherwise sit, all without any visible change to image quality.

### Active Content in SVG Files

SVG is an XML-based format that can legally contain scripts, event handlers, and external references, which is exactly what makes it attractive for phishing pages that decode a Base64 payload at runtime, a technique now tracked under [MITRE ATT&CK as SVG Smuggling](https://attack.mitre.org/techniques/T1027/017/). 

Because normal, trustworthy SVGs have no need for JavaScript, Deep CDR™ Technology removes script elements, strips CDATA sections that could conceal logic, blocks injected content, and [rebuilds a standards-compliant SVG](https://www.opswat.com/blog/how-to-stop-svg-based-phishing-attacks-with-deep-cdr) with only safe visual elements, with the option to rasterize the file entirely for workflows that do not need vector interactivity. 

In each case, Deep CDR™ Technology does not attempt to recognize the specific attack but removes the class of content the attack depends on, which is why the AV-Comparatives test results hold regardless of whether the malicious file was handcrafted or AI-assisted.

### Obfuscated URLs in QR Codes

QR code phishing relies on the fact that a human eye cannot read the destination URL encoded in the image, so the user has no way to judge legitimacy before scanning.

Deep CDR™ Technology decodes and surfaces the human-readable URL and can route it through a URL reputation check before delivery. If an image-based QR code also carries a steganographic payload, the same pixel-level sanitization used against image-borne malware applies here as well.

## Where This Leaves Detection

While modern AV engines routinely report detection rates north of 99%, there still leaves a residual sliver at a fraction of a percent in recent testing, where a novel or evasive threat gets through simply because no engine had seen anything like it yet.

Deep CDR™ Technology closes the gap that AV cannot close by its very design. However, none of this is an argument to retire antivirus or detection-based tooling, and AV-Comparatives is explicit on this point in its own conclusion: CDR should be viewed as a complementary control rather than a replacement for endpoint protection, EDR, or sandboxing.

OPSWAT MetaDefender Platform is built on such foundation where Deep CDR™ Technology, Predictive Alin AI, Metascan™ Multiscanning, AI Content Inspector, Proactive DLP™, Adaptive Sandbox, and other technologies are layered in a comprehensive file security workflow to provide complete protection against zero-day threats.

## Conclusion

The AV-Comparatives review is consistent with what earlier independent testing found: Deep CDR™ Technology's prevention-first sanitization holds against both conventional and AI-assisted file-borne threats, including zero-day exploits that have no available signature.

Prior independent evaluations from SE Labs and SecureIQ Lab reached the same 100% sanitization result for Deep CDR™ Technology.

As AI lowers the barrier to crafting convincing lure documents, obfuscated macros, and structurally deceptive payloads, shifting from detection-first to prevention-first cybersecurity posture is becoming less of a differentiator and more of a baseline requirement.
