Enables the dropper detection component to perform static analysis on the appliance.
This component allows the appliance to identify malicious files that might have installed additional types of malware on your system. A dropper is not associated with any file extensions, and it is often part of a spearphishing attempt. The appliance sends the dropper files that matched the first ten MD5 checksums to the Dynamic Threat Intelligence (DTI) Cloud for further analysis. When the dropper detection component is disabled, the appliance does not send the dropper files to the DTI Cloud.
The dropper detection component is enabled by default.
Syntax
[no] static-analysis dropper enable
Parameters
no
Use the no form of this command to disable dropper detection.
Example
The following example enables the dropper detection component to perform static analysis on the appliance:
hostname (config) # static-analysis dropper enable
User role
Admin and Operator
Command mode
Config
Supported appliances
This command is supported on the following appliances running the specified releases or later:
Network Security: Release 7.7
Email Security — Server: Release 7.8