Every NGFW vendor claims to stop zero-day threats. SonicWall backs this claim with two specific technologies — RTDMI (Real-Time Deep Memory Inspection) and Capture ATP — that work differently from each other and from what most competitors offer.
This guide explains exactly how both technologies work, how they complement each other, and why they matter for Indian businesses facing modern cyberattacks.
The Zero-Day Threat Problem
Traditional firewall threat detection relies on signatures — a database of known malware patterns. When a file arrives at the firewall, it is compared against the signature database. If there is a match, it is blocked; if not, it passes through.
This model has two fundamental weaknesses:
1. New threats: A zero-day threat — one that has never been seen before — has no signature. It passes through signature-based defences undetected.
2. Evasive threats: Sophisticated malware is designed specifically to evade detection. Common evasion techniques include:
- Polymorphism: The malware changes its own code signature each time it replicates
- Encryption: The malicious payload is encrypted until it reaches the target system
- VM detection: The malware detects that it is being analysed in a sandbox and changes its behaviour to appear benign
- Time delays: The malware waits minutes or hours before executing its payload — longer than most sandbox analysis windows
SonicWall addresses both weaknesses with RTDMI and Capture ATP.
What Is RTDMI?
Real-Time Deep Memory Inspection (RTDMI) is SonicWall's patent-pending technology for detecting threats at the processor memory level.
How RTDMI Works
Traditional sandboxing runs a suspicious file in an isolated virtual machine and watches what it does (creates registry keys, makes network connections, spawns processes). RTDMI takes a fundamentally different approach:
-
Force execution in a controlled memory environment: RTDMI causes the suspicious code to execute in a controlled memory space — not a full virtual machine, but a memory-level execution environment.
-
Inspect at the memory level: As the code executes, RTDMI inspects the machine code being loaded into processor memory. Malicious instructions — even if they were encrypted in the original file — must decrypt themselves to execute. RTDMI captures the decrypted form in memory.
-
Detect based on malicious intent, not appearance: RTDMI looks for malicious code patterns at the machine instruction level, not at the file level. A polymorphic virus that changes its file signature on every copy cannot change its fundamental machine code instructions — those are what RTDMI analyses.
Why RTDMI Cannot Be Evaded by Sandbox Detection
Traditional sandboxes can be detected by malware. A sophisticated virus will check:
- Is this running on real hardware or a virtual machine?
- How much time has elapsed since execution started?
- Are debugging tools present in memory?
- Are there fewer than N running processes? (indicators of a sandbox environment)
If the malware detects a sandbox, it simply does not execute its payload. The sandbox sees benign behaviour and passes the file.
RTDMI is not a virtual machine. There is no VM to detect. The code is forced to execute in memory — it cannot distinguish between running inside RTDMI and running on a target machine.
RTDMI Performance — 2024 Data
According to SonicWall's annual Cyber Threat Report:
- RTDMI discovered more than 1,500 previously unknown malware variants per day in 2024
- Over 325,000 net-new malware variants were discovered by RTDMI across the year
- RTDMI detections feed back into SonicWall GRID — the global threat intelligence network — making the detection faster for all SonicWall customers
What Is Capture ATP?
Capture Advanced Threat Protection is SonicWall's cloud sandboxing service. It operates as a complement to RTDMI — where RTDMI handles memory-level analysis, Capture ATP provides multi-engine file detonation in isolated cloud environments.
How Capture ATP Works
When a suspicious file is detected that warrants deeper analysis:
- File is sent to the Capture ATP cloud: The file is transmitted to SonicWall's Capture ATP data centres for analysis
- Multi-engine analysis: The file is detonated across multiple independent analysis engines:
- Full system emulation: Run the file on a complete virtual machine and observe all behaviour
- Virtualization: Hypervisor-based code analysis
- Lightweight scanning: Static and behavioural signature analysis
- RTDMI: Memory-level inspection (also run in the cloud)
- Verdict issued: If any engine flags the file, the verdict is Malicious. If all engines pass, the verdict is Clean
- Action at the gateway: Based on your policy, the firewall either blocks or allows the file
Block Until Verdict — The Critical Setting
The most important Capture ATP setting for Indian businesses is Block Until Verdict.
| Setting | Behaviour |
|---|---|
| Block Until Verdict: OFF | File is passed through immediately; Capture ATP analysis runs asynchronously; alert is generated if malicious (but the file is already on the network) |
| Block Until Verdict: ON | File is held at the gateway until Capture ATP returns a verdict; only released if the verdict is Clean |
Block Until Verdict should always be enabled. Without it, Capture ATP is a detection and alerting tool — not a prevention tool. The typical Capture ATP analysis time is a few seconds for most files; users experience a brief delay on the first access to a new file type.
RTDMI vs Capture ATP — How They Differ
RTDMI and Capture ATP are complementary, not competing:
| Factor | RTDMI | Capture ATP |
|---|---|---|
| Analysis location | On-device (in the appliance) | Cloud (SonicWall data centres) |
| Analysis method | Memory-level instruction inspection | Multi-engine file detonation |
| Speed | Milliseconds | Seconds (typically 3–15 seconds) |
| Evasion resistance | Very high — no VM to detect | Medium — advanced malware can detect VM |
| Coverage | Code execution paths | Full file behaviour |
| Internet required | No (runs on-device) | Yes (cloud analysis) |
| Block Until Verdict | Always immediate | Optional setting |
In practice, they work in sequence:
- RTDMI analyses suspicious code in real time as it arrives
- Files that pass RTDMI initial inspection but remain suspicious are queued for Capture ATP deep analysis
- Capture ATP returns a verdict; if malicious, the file is blocked (or already blocked if Block Until Verdict is on)
How Indian Businesses Are Targeted — Where RTDMI Helps
Ransomware delivered via email
The most common attack path for Indian SMBs. A user receives an email with an attached Word document or ZIP file. The attachment contains a macro or exploit that, when opened, downloads and executes ransomware.
RTDMI catches these at the file execution step — before the macro runs its download instruction. Capture ATP catches the downloader stage if the initial file appears benign but executes suspicious network connections.
Supply chain and software update attacks
An Indian software company's update server is compromised to deliver a backdoored update. The update binary has no signature because it is a legitimate-looking signed executable that was modified post-signing.
RTDMI analyses the binary in memory as it executes — the malicious code payload reveals itself in memory even if the file signature passes all other checks.
Fileless malware
Increasingly common in India — especially in BPO and BFSI sectors. Fileless malware never writes a file to disk; it executes entirely in memory via PowerShell scripts, WMI calls or injected shellcode.
Traditional file-based antivirus and sandboxing are blind to fileless attacks. RTDMI, operating at the memory instruction level, detects the malicious execution patterns even without a file to analyse.
Encrypted C2 traffic
After initial compromise, malware communicates with command-and-control (C2) servers over HTTPS. Most firewalls without TLS inspection cannot see this traffic.
SonicWall's DPI-SSL decrypts HTTPS traffic and passes the content to RTDMI and the IPS engine. C2 communication patterns are detected and blocked before the attacker can issue commands.
Does RTDMI Affect Firewall Performance?
RTDMI is designed to be a real-time process — it cannot introduce significant latency or it would break normal network operations.
SonicWall achieves this through hardware offloading on TZ 570+ and all NSa series appliances. The RTDMI analysis is performed by a dedicated security processing chip (OCTEON-based architecture), not the main firewall CPU. On smaller TZ appliances (TZ 270/370), RTDMI runs on the main processor — but the analysis is so fast that user-visible latency is typically below 1ms for most files.
Real-world throughput impact: With RTDMI and Capture ATP fully enabled, expect approximately 20–35% reduction in throughput vs. raw firewall throughput. This is consistent with all NGFW vendors running full DPI — ensure you are sizing the appliance based on Threat Prevention throughput, not raw Firewall throughput.
Comparing SonicWall to Other Vendors
| Vendor | Memory-Level Inspection | Sandbox Type | Sandbox Included |
|---|---|---|---|
| SonicWall | RTDMI (on-device) | Capture ATP (cloud, multi-engine) | Yes — in TotalSecure |
| Fortinet | No direct equivalent | FortiSandbox (separate appliance/cloud) | Add-on subscription |
| Sophos | No direct equivalent | Intercept X (endpoint-side) | Separate Endpoint product |
| Palo Alto | WildFire (cloud ML) | WildFire multi-engine | Add-on subscription |
| Check Point | ThreatCloud AI | SandBlast (cloud) | Add-on subscription |
Key takeaway: RTDMI is SonicWall's unique differentiator. No other SMB firewall vendor includes memory-level inspection as a standard capability in their base bundles. Most competitor sandboxing is an add-on that costs extra.
Activating RTDMI and Capture ATP on Your SonicWall
Step 1: Register your TotalSecure subscription
RTDMI and Capture ATP require an active TotalSecure subscription. Register at my.sonicwall.com using your appliance serial number.
Step 2: Enable Gateway Anti-Virus with RTDMI
In SonicOS: Security Services > Gateway Anti-Virus
- Enable on all zones (LAN, WAN, DMZ, VPN zones)
- Verify RTDMI shows as Active
Step 3: Enable Capture ATP with Block Until Verdict
In SonicOS: Security Services > Capture ATP
- Enable Capture ATP
- Enable Block Until Verdict
- Select file types to inspect (recommended: All)
Step 4: Monitor detections
Logs > Capture ATP: shows all files sent for analysis and their verdicts Logs > Event: shows RTDMI blocks and IPS events
As an authorised SonicWall partner in India, Cloudfy Systems configures RTDMI and Capture ATP correctly on every deployment — including Block Until Verdict and DPI-SSL settings that are often missed in self-managed deployments.
Contact us: +91 97600 50555 · connect@cloudfysystems.com
Frequently Asked Questions
Does RTDMI work offline?
Yes. RTDMI operates on the SonicWall appliance itself — it does not require an Internet connection to perform memory-level inspection. Capture ATP requires Internet access to send files for cloud sandboxing; if your Internet connection is down, Capture ATP analysis is unavailable but RTDMI continues to function.
How many zero-day threats does RTDMI find per day?
In 2024, SonicWall reported that RTDMI identified over 1,500 previously unknown malware variants per day across all deployed appliances. These discoveries feed back into the SonicWall GRID threat intelligence network, improving protection for all SonicWall customers.
Can RTDMI be disabled to improve performance?
Yes, but it is not recommended. Disabling RTDMI removes the primary defence against zero-day and evasive threats. If performance is a concern, the correct approach is to size up to the next appliance model rather than disabling security features.
Does Block Until Verdict slow down user browsing?
For most files (HTML, images, common document types that have been previously analysed), Capture ATP returns an instant cached verdict — no delay. For new, unknown files, the analysis typically takes 3–15 seconds. Users experience this as a brief delay when downloading a file for the first time. The delay is a deliberate design decision — it is the cost of genuine zero-day prevention.
