Home
EN
Location
Documentation Home
Palo Alto Networks
Support
Live Community
Knowledge Base
Clear
AutoFocus® API Reference
:
Analysis Artifacts
Updated on
Fri Sep 01 02:09:44 UTC 2023
Focus
Download PDF
Updated on
Fri Sep 01 02:09:44 UTC 2023
Focus
Home
AutoFocus
AutoFocus® API Reference
Perform AutoFocus Searches
Search Field Names
Analysis Artifacts
Download PDF
AutoFocus® API Reference
Analysis Artifacts
Table of Contents
Filter
Expand all
|
Collapse all
About the AutoFocus API
AutoFocus API Overview
AutoFocus API Prerequisites
AutoFocus API Rate Limits
Rate Limits and Points Allotment
How to Track Points
Points Usage
AutoFocus API Resources
Resources for Initiating Searches
Resources for Viewing Search Results
Resources for Direct Searches
AutoFocus API STIX Support
STIX Elements and Fields
Get Started with the AutoFocus API
Get Your API Key
Make Your First AutoFocus API Calls
Start a Search
View Results
Perform AutoFocus Searches
Search Samples and Sessions
Search Field Names
General Artifacts
Sample Artifacts
Session Artifacts
Analysis Artifacts
Linux Artifacts
Windows Artifacts
Mac Artifacts
Android Artifacts
Macro Artifacts
Search Parameter Types and Operators
Search Countries and Country Codes
Search Top Tags, Session Histogram, and Session Aggregate Data
Search for Signatures
View Search Results
Perform Direct Searches
Get Session Details
Get Sample Analysis
Get Tags
Get Tag Details
Get Threat Indicator Feed
Get Custom Threat Indicator Feed
Get Threat Intelligence Card Summary
Export List
Get Anti-spyware, Vulnerability, and File-Format Signature
Get Antivirus Signature
Get DNS Signature
Get Geolocation
Get Anti-spyware, Vulnerability, and File-Format Release Info
AutoFocus API Error Codes
AutoFocus API Error Codes
Analysis Artifacts
The following table provides field names and related information for analysis artifacts.
Field Name
Artifact Type as it Appears on AutoFocus Web Portal
Field Type
Acceptable Values and Examples
sample.tasks.connection
Connection Activity
StringProx
Network activity including connections, IP addresses, and country codes.
Example:
tcp-connection, 46.254.18.90:80 , , RU
sample.tasks.dns
DNS Activity
StringProx
DNS activity including query, response, and type.
Example:
a0ce.akamaiedge.net
sample.tasks.file
File Activity
StringProx
Parent process, action, and file path.
Example:
Program Files\Zona\utils.jar,
sample.tasks.http
HTTP Activity
StringProx
HTTP request including host, method, URL, and user agent string.
Example:
/T/a93E_X.jpeg
sample.tasks.metadata_sections
PE Metadata
StringProx
Metadata from PE files, including the name, virtual address, virtual size, and raw size.
Example:
.text , 15872 , 4096 , 15866
sample.tasks.japi
Java API Activity
StringProx
Java runtime activity.
Example:
load, class barcode.Get2D not found.
sample.tasks.behavior_type
Observed Behavior
StringProx
Behaviors seen when a sample is analyzed by WildFire.
Example:
pe_sa_abnl_sect_name
sample.tasks.misc
Other API Behavior
StringProx
Non-Java API activity seen when a sample is analyzed by WildFire.
Example:
sample.exe , ZwProtectVirtualMemoryFailed , 0xc0000045 , 0xffffffff , pid=1516 , 0x0012fed8 , 0x0012fedc , 0x00000000
sample.tasks.process
Process Activity
StringProx
Processes that showed activity when the sample was analyzed by WildFire.
Example:
cmd.exe , terminated , , Users\\Administratorexp lorer.exe"
sample.tasks.service
Service Activity
StringProx
Services that showed activity when the sample was analyzed by WildFire.
Example:
WINWORD.EXE , StartService , ,
sample.tasks.user_agent
User Agent Fragments
StringProx
The user agent header for HTTP requests sent when the sample was analyzed by Wildfire.
Example:
Microsoft-CryptoAPI/6.1
Previous
Session Artifacts
Next
Linux Artifacts