analysis retro-hunt enable

Prev Next

Enables or disables retroactive detection from AV-Suite.

When you enable retroactive detection from AV-Suite, the appliance queries the AV-Suite server for previous retroactive verdicts based on the submitted malware samples. When retroactive detection from AV-Suite is disabled, the appliance does not query the AV-Suite server for previous retroactive verdicts based on submitted samples.

For details about AV-Suite, refer to the following documents:

  • "System Configuration" chapter of the EX Series User Guide, Malware Analysis User Guide, and the File Protect User Guide

  • "Configuring Threat Management" chapter of the Network Security User Guide

  • "AV-Suite" chapter of the Intelligent Virtual Execution - Server Administration Guide

Retroactive detection from AV-Suite is enabled by default.

Note

Use the show static-analysis config command to verify that static analysis and AV-Suite integration are enabled on the appliance.

Syntax

[no] analysis retro-hunt enable

Parameters

no
Use the no form of this command to disable retroactive detection from AV-Suite on the appliance.

Example

The following example enables retroactive detection from AV-Suite on the appliance:

hostname (config) # analysis retro-hunt enable 
hostname (config) show analysis config
  .....

   Retroactive hunting                      : Enabled
  .....

The "Retroactive hunting" line displays "Enabled" to indicate that the appliance can access the previous results of the analysis that were stored in AV-Suite.

The following example disables retroactive detection from AV-Suite on the appliance:

hostname (config) # no analysis retro-hunt enable hostname (config) # show analysis config ..... Retroactive hunting : Disabled .....

The "Retroactive hunting" line displays "Disabled" to indicate that the appliance cannot access the previous results of the analysis that were stored in AV-Suite.

User role

Admin and Operator

Command mode

Config

Supported appliances

This command is supported on the following appliances running the specified releases or later:

  • Email Security — Server: Release 8.1.2.

  • Network Security: Release 8.2.0.

  • File Protect: Release 8.2.0.

  • Malware Analysis: Release 8.2.0.

  • Intelligent Virtual Execution - Server: Release 8.2.0.