You can configure the settings for retroactive detection from AV-Suite by using the Intelligent Virtual Execution - Server appliance CLI:
Configuring AV-Suite to store objects using the CLI
Configuring retroactive detection updates from AV-Suite using the CLI
You can configure how often the Intelligent Virtual Execution - Server appliance queries the AV-Suite server for previous retroactive verdicts. You can also configure how long you want to store information (filename, file type, engine type, MD5 checksum, and SHA-256 hash file) in AV-Suite for the malicious and nonmalicious objects and to check for a particular object to update. The verdict remains in AV-Suite but other information about the object is removed.
Administrator or Operator access to the Intelligent Virtual Execution - Server appliance
A two-way sharing CONTENT_UPDATES license
Verify that AV-Suite integration is enabled. Verify that AV-suite version 6 is configured. Use the
show static-analysis configcommand.Enable retroactive detection from AV-Suite. Use the
analysis retro-hunt enablecommand.