Skip to main content

Platform Requirements

Hardware and performance specifications for ReversingLabs virtual appliances and deployment profiles.

Spectra Analyze

SpecificationSpectra Analyze E-1KSpectra Analyze 5KSpectra Analyze E-15KSpectra Analyze 30K
ApplicationAnyAnyAnyAny
Included ModulesReversingLabs Sample Analysis ApplicationReversingLabs Sample Analysis ApplicationReversingLabs Sample Analysis ApplicationReversingLabs Sample Analysis Application
Spectra Core™ Pre-Execution / Static Analysis EngineSpectra Core™ Pre-Execution / Static Analysis EngineSpectra Core™ Pre-Execution / Static Analysis EngineSpectra Core™ Pre-Execution / Static Analysis Engine
Spectra Cloud™ File Reputation Web Services InterfaceSpectra Cloud™ File Reputation Web Services InterfaceSpectra Cloud™ File Reputation Web Services InterfaceSpectra Cloud™ File Reputation Web Services Interface
CPU8 cores16 cores24 cores32 cores
RAM64 GB96 GB128 GB256 GB
Storage Size1 TB2 TB3 TB4 TB
Storage MediaSSD-backedSSD-backedSSD-backedSSD-backed
Min. IOPS2000200020002000
Min. Throughput (MBps)300300300300
Network Throughput (Mbps)100100100100
AWS Instancer6a.2xlarge with 1 TB EBS gp3r6a.4xlarge with 2 TB EBS gp3r6a.8xlarge with 3 TB EBS gp3r7a.12xlarge with 4 TB EBS gp3

Spectra Analyze Platform Requirements are the minimum recommended specifications where file size must be under 400MB total and average size for all files under 250k for Spectra Analyze E-1K. Spectra Analyze 30K supports file sizes up to 10GB. For security hardening guidance applicable to deployment environments, refer to NIST SP 800-53 security controls.

For more deployment information, see Cloud Deployment Options and Firewall and Network Connections.


Spectra Detect

SpecificationSpectra Detect ManagerSpectra Detect HubSpectra Detect Worker
ApplicationAnyLarge-sized organizationsAny
Included ModulesCentral Management for AppliancesLoad BalancerSpectra Cloud™ File Reputation Web Services Interface
Central Status Overview for AppliancesLoad MonitorSpectra Core™ Pre-Execution / Static Analysis Engine
Central Update Management for AppliancesWeb Services API, Splunk Export
CPU8 cores8 cores32 cores
RAM64 GB64 GB128 GB
Storage Size2 TB1 TB2 TB
Storage MediaSSD-backedSSD-backedSSD-backed
Min. IOPS2000200040,000
Min. Throughput (MBps)9090600
Network Throughput (Mbps)100100800
AWS Instancem6a.xlarge with 2 TB EBS gp3m6a.xlarge with 1 TB EBS gp3See Worker Profiles below

Worker Profiles

The following table takes into account a single Worker. Varying specs imply different performance levels.

SpecificationProfile 1Profile 2Profile 3
Core count81632
Memory (GB)3264128
Disk (SSD)1TB1.5TB2TB
Performance (MB/sec)1.63.26.4
Files / day150,000300,000600,000
TB / day0.1250.250.5
Min Look-ups / day1,500,0003,000,0006,000,000
Max Look-ups / day7,500,00015,000,00030,000,000
Max file size1GB6GB200GB
AWS Instancem6a.2xlarge with 1 TB EBS gp3m6a.4xlarge with 1.5 TB EBS gp3m6a.8xlarge with 2 TB EBS gp3
note

The maximum file size depends on the content of the file, not only its size. Spectra Detect unpacks a submitted file and analyzes what's inside it, so the limit is governed by how much content the file expands into during analysis. This applies to every profile. The figures below were measured on Profile 3; Profile 1 and Profile 2 behave the same way at lower thresholds, because both the working storage and the memory available for analysis are smaller.

Content that expands little can go higher. In testing on Profile 3 hardware, an archive of model weights processed successfully at 400 GB. A single model file processed successfully at 200 GB.

Content that expands a great deal must stay lower. Compressed data such as parquet or gzipped text can expand seven times or more, and analyzing it is bound by available memory rather than by file size. In testing on Profile 3 hardware, a 50 GB archive of parquet data processed successfully, while archives of 75 GB and larger did not complete.

As a sizing guide, allow roughly three times the submission size in working storage for model content, and seven times or more for compressed data.

T1000

SpecificationT1000 R1T1000 XGT1000 Assure
ApplicationAnyAnyAny
Included ModulesFile Reputation Database - R1 set plus additional file threat classificationFile Reputation Database - XG set plus latest AV scan informationFile Reputation Database - XG set plus latest AV scan information
Web Services APIWeb Services APIWeb Services API
Database auto-updateDatabase auto-updateDatabase auto-update
CPU≥16 cores≥16 cores≥16 cores
RAM64 GB64 GB64 GB
Storage Size21 TB36 TB20 TB
Storage MediaSSD-backedSSD-backedSSD-backed
Min. IOPS20,00030,00030,000
Min. Throughput (MBps)250320320
Network Throughput (Mbps)250500500
VM Requirements