Shows the signature , source and other details of an SHA-256 hash file, URL, or MD5 checksum.
Syntax
show analysis intel url <URL>
show analysis intel sha256 <sha256>
show analysis intel md5 <md5>
Parameters
<URL>
URL address
<sha256>
The alphanumeric value of an SHA-256 hash file
<md5>
The alphanumeric value of an MD5 checksum
Output fields
The following table describes the output fields for the <show analysis intel> command. Fields are listed in the approximate order in which they appear in the output.
Field | Description |
|---|---|
Feed Type | The type of intel that is indexed (SHA-256/MD5/URL) |
Intel Class | Specifies if the URL or hash file is added to the Allowed List or Block List |
Source | The source where the hash was indexed from (eg: Custom, SC, GC, FAUDE, and LOCAL) |
Feed Name | The name of third party feed file or custom feed |
Signature | The malware signature of the indexed hash |
Example
The following example displays the details for the MD5 intel, "71189fb8eacea4299ced7b36f9d72b06".
hostname (config) # show analysis intel md5 71189fb8eacea4299ced7b36f9d72b06 Feed Type | Intel class | Source | Feed name | Signature ------------------------------------------------------------------- md5 | Allowlist | Custom | custom-md5-allowlist | custom-md5-allowlist md5 | Allowlist | SC | DTI | DTI-md5-AllowList
User role
Administrator
Command mode
Enable
Supported appliances
This command is supported on the following appliances running the specified releases or later:
Email Security — Server: Release 10.0.2
File Protect: Release 10.0.2
Malware Analysis: Release 10.0.2
Network Security: Release 10.0.2