Skip to main content
← Back to Demos
Country of Origin beginner · 15 min

Region-specific document origin analysis for policy decisions

Organizations increasingly enforce file policies based on geographic origin, but attackers routinely masquerade documents as coming from trusted regions — forging author metadata, adjusting language, and aligning timezone artifacts to evade policy checks (T1036.005). Country of Origin analysis examines metadata and content fingerprints — author names, language, timezone artifacts, and software version trails — to establish a document's true provenance, exposing mismatches between claimed and actual origin. The module surfaces this provenance so policy decisions — allow, quarantine, or block — can be enforced automatically. The demo uses a benign Office document, so no sensitive or malicious content is involved.

Attack Technique

Origin-based policy enforcement

MITRE ATT&CK

T1036.005 ↗

Platforms

linux

File Types

.xlsx

MetaDefender Capabilities

Country of Origin

Incident Coverage

This attack technique maps to a real-world security incident — read the daily digest for details: Read the incident digest ↗

--- ---