← Back to home

Coordinated coverage

Armor + FileWall. Two layers, one defense.

The suite includes two separate applications. Armor counters ransomware behavior in protected folders; FileWall sanitizes documents through a CDR pipeline before use.

Armor anti-ransomwareFileWall document CDRCombined purchase

Coordinated coverage

Complementary roles without conflating them.

Armor and FileWall do not perform the same job and are not a single engine: each retains its own interface, service, and operational workflow. Used together, they cover both process behavior affecting data and active content embedded in documents.

Armor

Protects folders through decoy files, heuristics, quarantine, allowlisting, and isolation.

FileWall

Intercepts, sanitizes, and rebuilds documents using policies, cache, and original-file quarantine.

Suite

Provides both products through one commercial path while keeping them technically distinct.

Technical deep dive

A pipeline that understands Portable Executable structure.

PEPack does not treat an executable as a generic archive. It reads headers, sections, and directories, determines what can be compressed without interfering with the loader, and builds a new layout with a coherent stub and metadata.

PEPack pipeline

PE analysis

Validates format, architecture, entry point, subsystem, sections, and loader-facing directories.

Planning

The profile selects algorithm, code, data, resources, cleanup, section names, integrity, and licensing.

Compression

Compresses only payloads allowed by the plan and keeps data required before the entry point separate.

Reconstruction

Emits the stub, publication sections, and required tables, then rebuilds the PE image.

Verification and save

Checks layout, requested integrity, and IAT manifest, produces the report, and writes the destination file.

Technical controls

Reduce size without ignoring the loader.

Compatibility depends on the executable, existing protections, and selected profile. PEPack keeps runtime-sensitive decisions visible and provides dedicated testing, analysis, and verification before distribution.

PE32 and PE64

LZMA uses a direct runtime decoder on PE32 and dedicated active publication sections on the PE64 path.

Resources and UAC

Resource compression retains on-disk material required for manifests, elevation behavior, and Explorer icons.

Integrity

The extended guard uses SHA-256 for the PE header and sections; the IAT manifest adds transparent import and IAT checks.

Built-in licensing

PEPack signs serials for packed executables with the profile private key and embeds only the public verification key in the runtime.

Available algorithms

AlgorithmProfileRuntime requirement
LZNT1Maximum compatibility and fast native decompression; lower compression ratio.Windows XP–11
XPRESSBetter ratio than LZNT1 with native Windows decompression.Windows 8 or later
XPRESS_HUFFBest ratio among native algorithms, with slower decompression.Windows 8 or later
LZMADefault high-ratio mode adapted to PE32 and PE64.Dedicated PEPack decoder

Packing changes binary structure: the result must be tested on every supported platform and signed again after transformation. Self-protected, already packed, or non-standard-layout applications may require a more conservative profile.

Coordinated coverage

Coverage that grows with your needs.

  1. Start with the layer that matters most
  2. Add the second product when needed
  3. Manage the suite through one commercial journey

Choose your solution

Buy