You can now import customized network attack rules. Network Attack Rules is a set of SNORT rules that are applied on the PCAP (Packet Capture) files of an analyzed sample. Intelligent Sandbox allows you to use your own SNORT rules to analyze and identify malicious activity in the network. Intelligent Sandbox applies the SNORT rule in the Current DAT file for malware detection. Network Attack Rules is available as a static analysis option in your analyzer profile.
Log on to the Intelligent Sandbox web interface.
Click → → .
Click the Network Attack Rules tab.
Next to Upload File, click Browse, then locate and select the ZIP file.
Note
You can import a maximum of two ZIP files that contains the SNORT rules and
classification.config. The second file that you upload becomes the Current file and renders the first version of the Backup files. The file size can be maximum of 200 MB.Click Upload.
If there are syntax errors in the file, Intelligent Sandbox displays the Uploaded file contains invalid Custom Behavioral Rules. Please check system log for more details. message.
If you delete the Current file, the Backup file replaces the Current file. To reinstate the Current file, click Revert.