Title
Create new category
Edit page index title
Edit category
Edit link
Threat Pattern Correlator - Support for Non-Executables
Enhancements to Threat Pattern Correlator now include support for all file types, improved speed, accuracy, and additional features for PE, resulting in an overall enhanced analysis experience.
All file type
Threat Pattern Correlator is applicable in numerous fields(close to 120 for all file types), but due to security reasons, we prefer not to disclose all of them. However, here are a few examples:
These features are carefully selected based on their ability to provide accurate and relevant results, and they are continuously updated to stay current with the latest malware trends and techniques.
| Feature group | Number of features |
|---|---|
| Apk | 22 |
| Biffopcodes | 1 |
| Emulation | 14 |
| Extracted | 10 |
| Extended data | 24 |
| Metadata | 15 |
| Segments | 6 |
| Sections | 6 |
| Strings | 5 |
| Threat indicators | 2 |
| Yara | 3 |
| Triggered consumer Ids | 1 |
Some of the features are:
| Field name | Type | Description |
|---|---|---|
| Metadata version code | String | Version code of the APK |
| ....(Other features ) | ..... | ..... |
| APK signers path | String | Path to APK signers |
| API events class name | String | Class name of API events |
| API events function name | String | Function name of API events |
Threat Pattern Correlator Filters
In addition to advanced technology, Threat Pattern Correlator provides multi filtering search parameters. This feature offers greater flexibility and ensures that users receive the most accurate and relevant results for their specific needs.
| Field name | Type | Possible values | Example | Description | Required |
|---|---|---|---|---|---|
| SHA-256 | String | Number | Yes | ||
| Submission data | Date | 2023-01-17T12:17:20.000Z | Number | Optional | |
| Final Verdict | String | MALICIOUS, LIKELY-MALICIOUS, NO-THREAT, SUSPICIOUS, BENIGN, UNKNOWN | MALICIOUS | Verdict of a file | Optional |
| Tags | String | peexe,xml | Tags of a file | Optional | |
| Threshold | Number | 1 to 100 any integer | Number | Similarity threshold 0% to 100% Higher score means higher similarity | Optional |
| Limit | Number | 1 to 100 any integer | Number | Number of returns | Optional |
See the "Technical Datasheet" for a complete list of features: https://docs.opswat.com/filescan/datasheet/technical-datasheet
