Complete the following configuration tasks to configure and perform malware analysis:
Prerequisites for malware analysis
Before you can complete the configuration tasks for malware analysis, ensure that the following prerequisites are met:
Set up the Intelligent Virtual Execution - Server appliance for the type of analysis that you want to deploy. For details about setting up the appliance for deployment, refer to the Hardware Administration Guide specific to your Intelligent Virtual Execution - Server model.
Configure the network, appliance settings, licenses, and user accounts. Verify that you have connection to the DTI Cloud or the Central Management System appliance. For details about configuring these settings, refer to the Malware Analysis System Administration Guide.
Install the guest images on the Intelligent Virtual Execution - Server appliance.
Configure the access point and user credentials for the network share. Verify that the Intelligent Virtual Execution - Server appliance can communicate with the network share site from your local machine before configuring the malware repository for unattended mode.
Configuring malware analysis
To configure malware analysis, complete the configuration tasks in the following order:
Determine the type of analysis that you want to configure.
Configure the settings for malware analysis using CLI.
Verify the settings for your malware analysis configuration.
Configure the settings of the .eml file to be analyzed. EML parsing is configured only using the CLI.
Performing malware analysis
After you have configured the sandbox or live malware analysis settings, you are ready to submit malware to the virtual machine for analysis. After you submit a malware sample to the Intelligent Virtual Execution - Server appliance, it is assigned a system-generated UUID. You can use this identifier to check the status of the submission.
After the malware has been analyzed, the Intelligent Virtual Execution - Server appliance can generate alert reports based on the results of the malware analysis.
To perform malware analysis, complete the configuration tasks in the following order:
Obtain malicious URLs.
Submit the malware to the virtual machine for analysis.
Verify the results of the completed malware analysis using CLI or a detailed report in web UI.