Filter WildFire Dynamic Analysis Processes and Activities

You can now filter the nested processes and activities content displayed in the WildFire Dynamic Analysis section of the sample details page. This allows you to remove extraneous or unnecessary content from cluttering up the sample details page.
  1. Start an AutoFocus™ search and click on a sample hash that has undergone WildFire® dynamic analysis.
    search-sample-results.png
  2. Scroll down to the WildFire Dynamic Analysis section and click on the filter icon ( filter_icon.png ).
    filter_process_activities.png
  3. Add analysis filters options.
    analysis_filter_start.png
    1. Add Filter
      to begin adding filter rules.
    2. Select the analysis filter
      Type
      .
      • Line Counts
        —AutoFocus filters activities that exceed the user specified artifact limits.
      • Regular Expression
        —AutoFocus filters activities matching with the specified regular expression. Items in the Parent Process and Parameters columns are evaluated for matches.
    3. Specify the analysis filter values.
      1. (
        Line counts only
        ) Specify the limits for each of the activity artifacts (
        Benign
        ,
        Malware
        , and
        Grayware
        ) and click
        Add
        . If you do want to specify limits for certain activity artifacts, you can leave those input boxes blank.
      2. (
        Regular expressions only
        ) Specify a regular expression in the
        RegExp
        text input box and click
        Add
        .
    4. Repeat steps 1-3 for additional analysis filters, otherwise
      Save changes
      .
  4. Scroll back down to WildFire Dynamic Analysis and view the activity sections. Filtered content is hidden by default but you can display them by clicking
    Show filtered lines
    .
    filter_process_show.png
  5. Filtered items that are displayed can be distinguished by the filter icon ( filter_icon.png ).
    filter_process_results.png
  6. Remove analysis filters conditions.
    filter_process_remove.png
    1. Click on the filter icon ( filter_icon.png ) to view the Analysis Filters.
    2. Click on the ( delete_icon.png ) next to the condition you want to delete, then
      Save changes
      .

Recommended For You