IOC scan results
The IOC alert processing result window displays the following information:
- In the File section:
- File size.
- Full path. Clicking the link with Full path opens a list in which you can select one of the following actions:
- SHA256. Clicking the SHA256 link opens a list in which you can select one of the following actions:
- Find on KL TIP.
- Find on virustotal.com.
- Find events.
- Find alerts.
- Create a prevention rule.
- Copy value to clipboard.
- MD5. Clicking the MD5 link opens a list in which you can select one of the following actions:
- The IOC section provides the XML code of the IOC file. The criterion by which the alert was generated is highlighted in yellow.
Page top