Malwation
Malwation is a Turkish cybersecurity R&D firm offering Threat.Zone, an agent-less malware analysis sandbox, and HookMesh, a CDR-based prevention platform, serving enterprise security teams and researchers via tiered SaaS subscriptions, APIs, and a global MSSP/reseller channel.
- Company typePrivate
- Founded2020
- HeadquartersPendik
- Headcount11–50
- GTM typeB2B
- OfferingSoftware
What Malwation does
Malwation Cyber Security Technology JSC is a privately held Turkish cybersecurity R&D firm founded in 2020 and headquartered at Teknopark, Pendik, Istanbul. The company develops two primary platforms: Threat.Zone, a cloud-based, agent-less malware analysis sandbox supporting Windows, Linux, macOS, and Android with hypervisor-level detection, static analysis, and emulation; and HookMesh, a malware prevention and Content Disarm and Reconstruction (CDR) platform that integrates with email gateways, file-sharing systems, and web applications via API. The company's underlying technology stack is built around deterministic sandboxing, automated deobfuscation (including the open-source Chiron .NET unpacker), and MITRE ATT&CK mapping, with a separate Malwation Threat Research (MTR) team producing published threat intelligence on malware families such as Agent Tesla, Origin Logger, and Snake Keylogger.
The company monetizes Threat.Zone and HookMesh through tiered SaaS subscriptions (Free, Researcher, and Hunter plans), a Public API, and an active channel partner program recruiting MSSPs, resellers, and distributors globally. Distribution is hybrid: self-serve PLG via app.threat.zone for individual researchers and SMBs, combined with enterprise sales into Turkish critical infrastructure customers including Turkish Airlines, Türk Telekom, Rekabet Kurumu (Turkish Competition Authority), and Al Baraka Banking, supported by AMTSO membership, Gold Sponsorship at Virus Bulletin 2024, and the 2024 e-Safe Cybersecurity Summit Malware Detection/Analysis award.
Malwation has completed three disclosed investment rounds totaling approximately $1.25M, with the most recent (~$1.05M) closed in December 2023 and led by Pragma alongside Arz Portfolio, Inveo Ventures, PCP, and Yıldız Tekno GSYO. Headcount is in the 11-50 range, and the company is led by founder and CEO Kağan İşildak alongside co-founder Osman Doğan. While the company maintains a stated global footprint, the named enterprise customer base is heavily concentrated in Turkey, signaling that international expansion via the partner program remains an early-stage commercial priority.
Malwation firmographics
Firmographics- Name
- Malwation
- Legal name
- Malwation Cyber Security Technology JSC
- Website
- https://malwation.com
- Company type
- Private
- Founded year
- 2020
- Operating status
- Operating
- Headcount range
- 11–50 employees
- Short description
- Malwation is a Turkish cybersecurity R&D firm offering Threat.Zone, an agent-less malware analysis sandbox, and HookMesh, a CDR-based prevention platform, serving enterprise security teams and researchers via tiered SaaS subscriptions, APIs, and a global MSSP/reseller channel.
- Ownership category
- akta.pro rank
Malwation industry classification
Industry- Product category
- Malware Analysis and Prevention Software
- NAICS
- Computer Systems Design and Related Services (54151)
- SIC
- Services-Computer Programming, Data Processing, Etc. (7370)
- akta.pro primary industry
- Deception Technology & Threat Hunting (HDADAGAI)
Keywords
Where Malwation is headquartered
LocationHeadquarters
- HQ city
- Pendik
Offices1 record
Markets served
Malwation business model
Business model- GTM type
- B2B
- Offering type
- Software
- Cost components
- Personnel, Technology or R&D, Marketing or Sales, Infrastructure, Operations
Revenue model
- SaaS Malware Analysis Platform (Threat.Zone): Threat.Zone is offered as a cloud-based malware analysis platform with tiered subscription plans (Free, Researcher, Hunter plans). The platform includes modules like CDR, CSI, and MemProcFS as included or add-on features depending on the plan tier. Version history shows progressive feature additions and module marketplace expansions indicating a modular SaaS model.
- HookMesh Malware Prevention Platform: HookMesh is sold as a malware prevention and CDR platform, likely through subscription licensing based on plan tiers and modules.
- Partner/Reseller Model: Malwation招募resellers, distributors, and MSSPs to resell and distribute their cybersecurity solutions to end customers.
- Threat.Zone Public API: Threat.Zone offers a Public API accessible through specific plan tiers, generating revenue from developers and organizations integrating the platform programmatically.
Pricing tiers
| Model | Billing | Price |
|---|---|---|
| Freemium | Monthly | Free Plan - Limited access to Threat.Zone features including file submission, HTML report, and additional file downloads |
| Subscription | Annual | Researcher Plan - Full analysis capabilities with CDR and CSI modules included |
| Subscription | Annual | Hunter Plan - All 3 modules (MemProcFS, CDR, CSI) included |
Go-to-market motion2 records
Distribution channels4 records
Marketing channels9 records
Malwation product offering
Product offeringCore offering
Malwation sells two flagship cybersecurity software platforms. Threat.Zone is a cloud-based holistic malware analysis sandbox supporting Windows, Linux, macOS, and Android with advanced static analysis, emulation, hypervisor-level detection, and anti-evasion tactics. HookMesh is a malware prevention and Content Disarm and Reconstruction (CDR) platform that integrates with existing security tools via API connections and automated workflow orchestration. Both platforms serve enterprise security teams, MSSPs, and threat researchers.
Product overview
Malwation offers a cybersecurity product portfolio centered on two core platforms: Threat.Zone (a holistic malware analysis sandbox supporting Windows, Linux, macOS, and Android with advanced static analysis, emulation, hypervisor-level detection, and anti-evasion capabilities) and HookMesh (a malware prevention platform that integrates with existing security tools via API connections, featuring automated workflow orchestration and Content Disarm and Reconstruction technology). Both products leverage shared underlying technologies including Sandbox, Static Analysis, and CDR to provide comprehensive malware analysis, sanitization, and simulation solutions for enterprise defense.
Differentiator
Problem solved
Functional benefit
Brands
- Threat.Zone: Holistic Malware Analysis Platform providing automated malware analysis with advanced sandbox technologies supporting Windows, Linux, MacOS, and Android. Features include static malware analysis, emulation capabilities, hypervisor-level detection, and anti-evasion tactics.
- HookMesh
- MTR (Malwation Threat Research)
Products and services
- Threat.Zone Holistic malware analysis platform (SaaS sandbox) supporting Windows, Linux, macOS, and Android. Provides advanced static malware analysis, emulation, hypervisor-level detection, and anti-evasion tactics for enterprise security teams, MSSPs, and threat researchers. Sold via tiered subscription plans (Free, Researcher, Hunter) with add-on modules (CDR, CSI, MemProcFS) and a public API.
- HookMesh
Quantifiable outcome
- Agent-less design works effectively against sandbox-aware malware, enabling stealthy analysis where agent-based sandboxes fail
- +3 more outcomes
Companies that use Malwation
Customer profileNamed customers10 records
Segments5 records
Ideal customer profiles4 records
Malwation technology and API
TechnologyTechnology focussed Yes
API detail
- Has API
- Yes
- API docs
- API detail
Core technology
AI maturity
App detail
Feature10 records
Malwation partnerships and signals
Strategic signalScale indicators6 records
Recent moves7 records
Expansion highlights6 records
Malwation competitors and assessment
Company assessmentDirect peers
- ANY.RUN: Interactive cloud-based malware analysis sandbox serving SOC analysts, researchers, and enterprise security teams with tiered subscription. Directly comparable to Threat.Zone in target customer, interactive analysis workflow, and subscription SaaS model.
- Joe Sandbox: Deep malware analysis sandbox with hypervisor-based detection supporting Windows, Linux, macOS, Android, and iOS. Closely comparable to Threat.Zone on technology depth, multi-OS coverage, and enterprise/research customer base.
- VMRay: Hypervisor-based malware analysis and detection platform targeting enterprise security teams with emphasis on agent-less, evasion-resistant analysis. Highly comparable to Threat.Zone on architecture and enterprise GTM, with overlap in phishing/malware sandbox use cases.
- Hatching Triage: Cloud-native automated malware analysis sandbox used widely by researchers and SOC analysts for high-volume sample triage. Directly comparable to Threat.Zone's automated sandbox workflow and PLG-style researcher adoption.
- Intezer Analyze: Malware analysis platform using genetic code reuse analysis to classify threats, sold to enterprise SOC and IR teams. Comparable to Threat.Zone in addressing malware triage/classification and serving similar security operations personas.
- Votiro: Content Disarm and Reconstruction (CDR) vendor providing file sanitization for email, web upload, and file sharing workflows. Most directly comparable to HookMesh's CDR functionality and zero-trust file sanitization positioning.
- Glasswall Solutions: CDR/file sanitization vendor for email, web, and file transfer security with deterministic zero-trust approach. Directly comparable to HookMesh on CDR technology, use cases (email gateway, file sharing), and enterprise/government customer segments.
Broad incumbents
- VirusTotal: Google-owned multi-engine malware/file scanning platform with massive corpus and free public sandbox. Comparable to Threat.Zone as a multi-engine malware analysis reference, though it operates as a broad incumbent with a wider portfolio than Malwation's focused sandbox.
- ReversingLabs: File and software security analysis platform offering static/dynamic analysis, malware classification, and threat intelligence for enterprise and supply-chain security use cases. Overlaps with both Threat.Zone (sandbox analysis) and HookMesh (file sanitization/CDR adjacency).
- OPSWAT (MetaDefender): Broad cybersecurity platform offering multi-scanning, CDR (MetaDefender), sandbox, and file security across email, web, and removable media. Overlaps with both Threat.Zone (sandbox) and HookMesh (CDR) as a larger incumbent with embedded OEM distribution.
Market position
Strengths5 records
Weaknesses4 records
Competitive moat5 records
Key risks5 records
Key highlights7 records
Customer concentration
Malwation social profiles
Digital presenceMalwation financial estimates
Financial estimateRevenue estimate
Valuation estimate
Malwation leadership team
Management profileNumber of profiles
Profiles6 records
Malwation funding detail
Funding detailFunding overview
Funding rounds3 records
Investors6 records
Funding detail is available on the Subscription and Enterprise plan.Contact sales →
Malwation M&A and investment
M&A and investmentM&A
Investments
M&A and investment is available on the Subscription and Enterprise plan.Contact sales →
Frequently asked questions about Malwation
What does Malwation do?
Malwation sells two flagship cybersecurity software platforms. Threat.Zone is a cloud-based holistic malware analysis sandbox supporting Windows, Linux, macOS, and Android with advanced static analysis, emulation, hypervisor-level detection, and anti-evasion tactics. HookMesh is a malware prevention and Content Disarm and Reconstruction (CDR) platform that integrates with existing security tools via API connections and automated workflow orchestration. Both platforms serve enterprise security teams, MSSPs, and threat researchers.
Is Malwation a public or private company?
Malwation is a private company. It is classified as venture growth investor backed and is currently operating.
When was Malwation founded?
Malwation was founded in 2020. It employs 11 to 50 people.
Where is Malwation based?
Malwation is headquartered in Pendik.
How does Malwation make money?
Four revenue lines are on record. SaaS Malware Analysis Platform (Threat.Zone) is the primary driver. The others are hookMesh Malware Prevention Platform, partner/Reseller Model and threat.Zone Public API.
Who are Malwation's main competitors?
Direct peers on record are ANY.RUN, Joe Sandbox, VMRay, Hatching Triage, Intezer Analyze, Votiro and Glasswall Solutions. Broad incumbents are VirusTotal, ReversingLabs and OPSWAT (MetaDefender).
Does Malwation have an API?
Yes. Threat.Zone Public API allows users to submit files, install additional files (Memory Dumps, PCAP Dumps), download submission samples and HTML reports, and access public submissions. API support varies by plan - plans page indicates which plans have API Support.
What industry is Malwation in?
Malwation's product category is Malware Analysis and Prevention Software. Its primary akta.pro industry code is HDADAGAI, Deception Technology & Threat Hunting. Its NAICS code is 54151 and its SIC code is 7370.