View event logs

Prev Next

When you submit a sample file for dynamic analysis, Intelligent Sandbox captures Windows events and WMI call traces. This includes application, system, security Windows events. Intelligent Sandbox allows you to search for suspicious strings and events through Windows event logs. Some samples do not generate event logs within the timeout period, therefore event logs are not displayed in the user interface. There is a possibility that only a few events will be captured, and the user interface will only display events that occurred within the timeout period.

  1. To enable Windows event logs, go to Analyzer Profile and select Event Logs from Reports, Logs, and Artifacts.

  2. Log on the Intelligent Sandbox web interface.

  3. Select AnalysisManual UploadBrowse, then locate and open the file you want to submit for analysis.

  4. Select the analyzer profile from the Analyzer Profile dropdown list.

  5. Select the priority from the Submission Priority dropdown list.

  6. Click Submit. The sample is uploaded to Intelligent Sandbox and is analyzed.

  7. Navigate to AnalysisAnalysis Reports. The Analysis Reports page lists the status of the file.

  8. Right-click the report GUID-B5B4CEAC-0E1F-4067-9ABA-8A273A2EFCFF-low.png and select Event Logs.