Skip to content

automation of sandbox analysis #672

Answered by jshcodes
NSH531 asked this question in Q&A
Discussion options

You must be logged in to vote

Hi @NSH531 -

Thank you for the question!
This is a complex ask, that could be solved several different ways. (Everyone approaches boiling the ocean a little bit differently.)

In an effort to try and answer this as succinctly as possible, I'm going to scope this down a bit and make a couple of assumptions based upon my understanding of your question.

Note: We don't submit an indicator to the sandbox. We upload a file to the sandbox, analyze it, and then submit the hash that is returned from the upload as an indicator.

Assumptions

  • An indicator in this particular scenario is a file that has been returned from Falcon X (ML or Quick Scan) as malicious that we then use to create a custom IOC.

Replies: 1 comment

Comment options

You must be logged in to vote
0 replies
Answer selected by ChristopherHammond13
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Category
Q&A
Labels
iocs IOCs (both) issues and questions Falcon Intelligence Falcon Intelligence issues and questions API usage General API usage issues and questions
2 participants
Converted from issue

This discussion was converted from issue #670 on May 27, 2022 01:50.