AV-Suite is a cloud-based detection service that stores verdicts for both malicious (blacklist) and nonmalicious (whitelist) objects. Information about a sample is sent to AV-Suite by the Intelligent Virtual Execution - Server appliance. This service is accessed by the Intelligent Virtual Execution - Server appliance using the AV-Suite Integration feature to provide verdicts based on advanced detection analytics in the cloud. Because dynamic analysis can be slow, AV-Suite helps to ensure the optimal appliance and analysis engine performance by not submitting samples that were whitelisted by AV-Suite to dynamic analysis.
Before an object is submitted to the Intelligent Virtual Execution - Server appliance for dynamic analysis, the appliance queries the AV-Suite server for a verdict. If a clean verdict is returned from AV-Suite for the file, the Intelligent Virtual Execution - Server appliance will not analyze the file for malicious content and the appliance will not perform dynamic analysis for this sample. If a malicious or riskware verdict is returned from AV-Suite, the Intelligent Virtual Execution - Server appliance will still perform dynamic analysis to generate an OS Change report.
When retroactive detection is enabled on the appliance, the appliance can alert on previously undetected objects. The Intelligent Virtual Execution - Server appliance can alert on previously undetected objects when a new verdict is generated for that object within the DTI Cloud.
Task list for managing AV-Suite
Complete the steps for managing AV-Suite in the following order:
Log in to the CLI.
Validate DTI access on the Intelligent Virtual Execution - Server appliance by using the
show fenet statuscommand. For details about how to validate DTI access, see Validating DTI access.Verify that "unity.fireeye.com" is used as the DTI server destination for AV-Suite to store both blacklist and whitelist object hashes and analysis results. Use the
show fenet dti configurationcommand. For details about how to set the DTI server destination for AV-Suite, see "Changing the active setting for a DTI service.Verify that AV-Suite integration is enabled and that AV-suite version 6 is configured. Use the
show static-analysis configcommand. For details about AV-Suite integration, see Enabling AV‑suite integration using the CLI or Disabling AV-suite integration using the CLI.Enable static analysis and AV-Suite integration on whitelist submissions. For details about how to enable AV-Suite Integration on whitelist submissions, see Enabling or disabling AV-suite integration on whitelist submissions using the CLI.
Enable retroactive detection from AV-Suite. Use the
analysis retro-hunt enablecommand. For details about how to enable retroactive detection from AV-Suite, see Enabling or disabling retroactive detection from AV-suite.Configure the settings for retroactive detection from AV-Suite. For details about how to configure the settings for retroactive detection from AV-Suite, see Configuring retroactive detection from AV-Suite.