show static-analysis config

Prev Next

Displays the AV-Suite, AV-Check, embedded object, YARA, reset binary analysis cache configuration settings, Dropper Detection, embedded URL analysis settings, and Python-based static analysis tool settings.

Syntax

show static-analysis config

Parameters

None

Example

The following example displays AV-Suite, AV-Check, embedded object, YARA, reset binary analysis cache configuration settings, Dropper Detection, embedded URL analysis settings, and Python-based static analysis tool settings.

hostname (config) # show static-analysis config
  Static Analysis enabled                : yes
    AV-suite enabled                     : yes
    AV-suite version                     : 6
    SA on AV-suite whitelist enabled     : no
    AV-check enabled                     : yes
    Dropper enabled     a                 : yes
    YARA enabled                         : yes

  Embedded object extraction enabled     : yes
  Embedded URL extraction enabled        : yes
  Max URLs From Files To Be Analyzed     : 5
  Static info policy                     : Enable
  Yara Configuration
    Yara policy                          : both
    Yara customer match limit            : 5
  Mobile Threat Prevention               : yes

User role

Administrator, Operator, Analyst, or Monitor

Command mode

Enable

Supported appliances

This command is supported on the following appliances running the specified releases or later:

  • Malware Analysis: Release 7.5. The command output was enhanced to include the settings for Intrinsic Analysis, AV-Check, and the Python-based static analysis tool in Release 7.7. The command output was enhanced to include whether AV-Suite integration on whitelist submissions is enabled in Release 8.2.

  • Email Security — Server: Release 7.5. The command output was enhanced to include static analysis if the attachment contains an allowed file type, and it has been disabled for analysis from the file association in Release 7.6.0. The command output was enhanced to include the settings for Dropper Detection, Intrinsic Analysis (DTI or local), AV-Check, and the Python-based static analysis tool in Release 7.8. The command output was enhanced to include the embedded URL analysis settings in Release 7.9. The command output was enhanced to include the AV-suite version in Release 8.0. The "Analysis of URLs Embedded in Files enabled:" line was replaced with the "Embedded URL extraction enabled:" line in Release 8.0. The "List of File to Extract URLs From:" line was removed in Release 8.0. The command output was enhanced to include whether AV-Suite integration on whitelist submissions is enabled in Release 8.1.2. The "AV-suite version" line was removed in Release 8.2.1. Intrinsic Analysis (DTI or local) was removed in Release 8.2.

  • File Protect: Release 7.5. The command output was enhanced to include the settings for Intrinsic Analysis, AV-Check, and the Python-based static analysis tool in Release 7.7. The command output was enhanced to include whether AV-Suite integration on whitelist submissions is enabled in Release 8.2.

  • Network Security: Release 7.5. The command output was enhanced to include the settings for Dropper Detection, Intrinsic Analysis, AV-Check, and the Python-based static analysis tool in Release 7.7. The command output was enhanced to include the settings for Intrinsic Analysis (DTI or local) in Release 7.9. The command output was enhanced to include whether AV-Suite integration on whitelist submissions is enabled in Release 8.2.

  • Intelligent Virtual Execution - Server: Before Release 8.0. The command output was enhanced to include whether AV-Suite integration on whitelist submissions is enabled in Release 8.2.