Ultralight contains the following key features: • Detects and blocks exploits, common malware, and other identifiers in any hostile content sent by attacker • Detects and blocks exploitive behavior occurring in an application designed to open potentially harmful content (PDF reader, office soft- ware, Java runtime, JavaScript interpreter, etc.)• Detects and blocks suspicious or malicious behavior both in running applications and in the system itself • Prevents compromised applications from performing hostile actions, such as dropping malware onto a system • Detects and blocks malware with a traditional file scanning engine • Detects and blocks memory-resident malware • Removes or quarantines malicious artifacts from the system • Disinfects objects that have been modified by file infectors • Utilizes WithSecure's™ Security Cloud to detect anomalies in files or file metadata • Sends suspicious executable files to WithSecure's™ Security Cloud for extended analysis • Prevents malware from contacting a C&C server • Uses automatic forensics and computer ecosystem anomaly detection to detect malware that other techniques are unable to prevent or detect