Web UI tabs

Prev Next

The Malware Analysis Web UI contains the following tabs.

Tab

Description

Dashboard

Overview of malware analysis and appliance status information. See “The Appliance Dashboard” topic in the Malware Analysis System Administration Guide .

Analysis

Filters used to submit malware analysis jobs and expandable levels of detailed information about the hosts that are infected in the network, callback activity, and malware attacks.

Settings

Tabs used to configure appliance and threat management settings:

Date and Time—Set the date and time manually or specify one or more Network Time Protocol (NTP) servers for automatic time synchronization.

User Accounts—Add and modify user accounts, including passwords, role assignments, and local access status, and reset your own password if you are assigned the Admin role.

My Account—Reset your own password, if you are assigned the Monitor, Operator, Analyst, or Operator role.

Email—Configure the appliance email account used for system notifications.

DTI Network—Specify the frequency of security and statistical content uploads.

Notifications—Configure event notifications for analysis alerts, and download the Trellix Management Information Base (MIB) file.

Network—View management interface settings and configure Domain Name Service (DNS) settings.

Malware Analysis—Configure settings for either sandbox or live mode forensic malware analysis.

Malware Repository—Configure a network share for each guest image from which files are regularly retrieved and analyzed by the Malware Analysis appliance.

Malware File Assoc.—View and customize the file types and applications that are used by guest images to perform malware analysis.

YARA Rules—Upload YARA rule files to quickly analyze large quantities of files for relevant matches.

Guest Images—View information about the currently loaded guest images (virtual machines) that test traffic and software for malicious activity.

Certificates—Upload SSL certificates.

Appliance Database—Perform appliance database operations.

Login Banner—Configure banner text that is displayed when a user logs in to the appliance CLI and Web UI.

Data Retention Policy - Configure the number of days to retain appliance data and schedule purging frequency.

Reports

Filters used to generate and download or schedule consolidated alert details reports, and links to download the schema for operating system changes and alerts.

About

Network administration information and controls:

Health Check— Appliance and system health information.

Log Manager—Filters used to specify log categories and time periods, and buttons used to create, download, upload, and delete log files.

Update—Security content, appliance image, and guest images status; and buttons used to check, download, and install security content, appliance images, and guest images.