The NDR Series appliance can extract a suspicious file from the network session and send it directly to the AX Series appliance for analysis.
Prerequisites
NDR Series appliance integrated with an AX Series appliance.
Sending files to AX for analysis
You will need a reconstructed session to submit a file to AX Series appliance. See Reconstructing a session.
Before submitting the file for analysis, you can select the profile to use when running the analysis. The profile is the virtual machine's operating system. You can also select the application within the profile.
The NDR can send a maximum of 10 simultaneous file submissions to the AX.
For details about how the malware affects the virtual machine, you can pivot to the AX. For more information about malware analysis, see the AX Series Threat Management Guide.
Note
The AX must be configured before you submit the file. If the AX is not configured, an error message appears.
Click
and from INVESTIGATION, select Search.Go to a reconstructed PCAP. You see the extracted file on the right side.
Select Send to AX.
Select the profile you would like to submit. For example, win7x64-sp1.
Select the application that you would like to run. For example, Chrome 36.0.
Select Submit.
Viewing Malware Analysis progress and results
After you submit a file to the AX Series appliance for malware analysis, you can view the progress in the NDR Web UI. There is one submission for each profile. When the analysis completes, the Malicious column displays the results. "Yes" means it is malicious and "No" means it is not malicious. "Err" means that there was an error during submission or analysis. If you see an error, you should run the file for analysis.
You must pivot to the AX Series appliance for the detailed analysis. For more information about malware analysis, see the AX Series Threat Management Guide.
Click
and from INVESTIGATION, select Malware Analysis.View the status in the Malicious column.
Click View on AX to pivot to the AX Series appliance for detailed analysis.