Enabling dropper detection using the CLI

Prev Next

This procedure describes how to use CLI commands to re-enable the dropper detection component of static analysis. Dropper detection is enabled by default. You can disable and re-enable dropper detection by using CLI commands only. When dropper detection is re‑enabled, no other configuration is required.

Prerequisites
  • Operator or Admin access.

  • Static analysis is enabled on the appliance. Check the "Static Analysis enabled" field in the output of the show static‑analysis config command.

To enable the dropper detection component of static analysis:
  1. Go to CLI configuration mode.

    vx-hostname > enable
    vx-hostname # configure terminal
  2. Enable the dropper detection component.

    vx-hostname (config) # static-analysis dropper enable
  3. Verify that the dropper detection component is enabled .

    vx-hostname (config) # show static-analysis config
     
    Static Analysis enabled                : yes
      AV-suite enabled                     : yes
      AV-suite version                     : 6
      SA on AV-suite whitelist enabled     : no
      AV-check enabled                     : yes
     Dropper enabled                      : yes
      YARA enabled                         : yes
     
    Embedded object extraction enabled     : no
    Embedded URL extraction enabled        : yes
    Max URLs from files to be analyzed     : 5
    Static info policy                     : Disable
    
    Yara Configuration
      Yara policy                          : both
      Yara customer match limit            : 5
      ........
  4. Save your changes.

    vx-hostname (config) # write memory