malware-intrinsic-analysis dti

Prev Next

Enables the appliance to send a request to the DTI Cloud to perform an analysis that compares objects against a larger set of known malware families. Objects that match known malware families are marked as malicious. The appliance can upload malware samples to the DTI network for analysis with a two-way content license.

By default, the DTI service is enabled for Intrinsic Analysis.

Note

The appliance must have a two-way sharing CONTENT_UPDATES license installed.

Note

Verify that AV-Suite integration is enabled on the appliance. Use the show static-analysis config command. If AV-Suite integration is not enabled, objects will be analyzed locally on the appliance.

Note

Verify that static analysis is enabled on the appliance. Use the show static-analysis config command.

Note

Verify that Intrinsic Analysis is enabled on the appliance. Use the show static-analysis config command.

Syntax

malware-intrinsic-analysis dti

Parameters

None

Example

The following example shows that Intrinsic Analysis is disabled and the configuration cannot be changed:

hostname (config) # malware-intrinsic-analysis dti
% Malware Intrinsic Analysis(MIA) is currently disabled. Cannot change MIA configuration. Please enable MIA to change configuration.

User role

Admin or Operator

Command mode

Config

Supported appliances

This command is supported on the following appliances running the specified releases or later:

  • Email Security — Server: Release 7.8

  • Network Security: Release 7.9