The following table explains the information available on the Enrichment Results home page, and indicates which columns are displayed by default.
Column Name | Description | Default Display |
|---|---|---|
MD5 | The MD5 hash of the file. | Yes |
Status | The status of the enrichment request. Possible values include the following:
| Yes |
Created | The date and time that the enrichment request was submitted. | Yes |
SHA256 | The SHA256 hash of the file. | Yes |
SHA1 | The SHA1 hash of the file. | Yes |
Size | The size of the file. | Yes |
MVX Verdict | The verdict received from MVX. Possible values include the following:
| Yes |
Trellix Verdict | The detection conclusion returned from the context API. Possible values include the following:
| Yes |
Trellix Analysis Conclusion | The analysis conclusion from the context API. | Yes |
Threat Names | The CSV list of malware names received from MVX. | Yes |
Risk Level | The level of risk returned from the context API. | Yes |
Type | The type returned from the context API. | Yes |
Mime Type | The media type returned from the context API. | Yes |
Alert URLs | The CSV list of the URLs to the alerts generated by MVX. | Yes |
First Seen by FireEye | The date and time when the file was first encountered and reported by the context API. | Yes |
Last Seen by FireEye | The date and time when the file was most recently encountered and reported by the context API. | Yes |
Count | The number of times the file has been encountered and reported by the context API. | Yes |
Labels | The CSV list of labels returned from the context API that are associated with the file. | Yes |
Risk Summary | The risk summary returned from the context API for the file. | Yes |
MVX Severity | The level of severity for the file as determined by MVX. Possible values are Critical, Major, Low, or Minor. | No |
MVX Malicious Class Type | The class or type of malicious file to which the file belongs. | No |
MVX Malicious Message | The malicious alert message returned from MVX. | No |
MVX Type | The data source that provided the Enrichment; Malware Analysis, Local Virtual Execution, or Intelligent Virtual Execution - Cloud. | No |
Trellix Description | The description returned from the context API. | No |
Trellix Kill Chain Phases | The CSV list of kill chain phases returned from the context API. | No |
Network Traffic Source Address | The source address of the network traffic returned from the context API. | No |
Network Traffic Destination Address | The destination address of the network traffic returned from the context API. | No |
Network Traffic Source Domains | The CSV list of network traffic source domains returned from the context API. | No |
Network Traffic Destination Domains | The CSV list of network traffic destination domains returned from the context API. | No |
Threat Actors | The CSV list of threat actors returned from the context API. | No |
Threat Labels | The CSV list of threat labels returned from the context API. | No |
Vendors | The CSV list of antivirus vendors returned from the context API. | No |
Total Vendor Scanned | The total number of antivirus vendors scanned and returned from the context API. | No |
Total Vendor Malicious | The total number of antivirus vendors reporting the file sample as malicious returned from the context API. | No |
Vendor Confidence | The maximum antivirus vendor confidence returned from the context API. | No |