Configuring retroactive detection from AV-Suite

Prev Next

You can configure the settings for retroactive detection from AV-Suite by using the Intelligent Virtual Execution - Server appliance CLI:

  • Configuring AV-Suite to store objects using the CLI

  • Configuring retroactive detection updates from AV-Suite using the CLI

You can configure how often the Intelligent Virtual Execution - Server appliance queries the AV-Suite server for previous retroactive verdicts. You can also configure how long you want to store information (filename, file type, engine type, MD5 checksum, and SHA-256 hash file) in AV-Suite for the malicious and nonmalicious objects and to check for a particular object to update. The verdict remains in AV-Suite but other information about the object is removed.

Prerequisites
  • Administrator or Operator access to the Intelligent Virtual Execution - Server appliance

  • A two-way sharing CONTENT_UPDATES license

  • Verify that AV-Suite integration is enabled. Verify that AV-suite version 6 is configured. Use the show static-analysis config command.

  • Enable retroactive detection from AV-Suite. Use the analysis retro-hunt enable command.