By default, WildFire™ dynamic analysis results
for a sample are grouped based on activity type (the WildFire analysis
Now, you can also view WildFire dynamic analysis
results based on the order in which activities were seen when the
sample was executed in the WildFire sandbox. For each operating
system in which the sample was executed, the sequence of events
that took place in the operating system kernel space and the operating
system user space is provided.
Notice that the analysis results for the sample are sorted
based on WildFire behavior and activity categories:
Click the new option
Show in Sequence
Select the drop-downs to view the user space and kernel
space event sequences:
User Space Event Sequence
lists the user space activities recorded when the sample underwent
WildFire dynamic analysis. User space is the memory area outside
of the operating system kernel, where applications and other user
processes are executed.
Kernel Space Event Sequence
lists the kernel activities recorded when the sample underwent WildFire
dynamic analysis. The kernel is the core of the operating system;
the kernel space is a memory area where the kernel runs operating
system processes and manages other processes.