Export Artifact Metadata
Table of Contents
Expand all | Collapse all
-
- New Features October 2020
- New Features September 2020
- New Features: August 2020
- New Features: April 2020
- New Features: November 2019
- New Features: May 2019
- New Features: March 2019
- New Features: February 2019
- New Features: November 2018
- New Features: October 2018
- New Features: September 2018
- New Features: August 2018
- New Features: July 2018
- New Features: June 2018
Export Artifact Metadata
When exporting artifacts from AutoFocus to
a CSV file, you can now also export the following information in
the CSV for each artifact:
- the export list label used to group artifacts,
- the time the artifact was added to the export list,
- the user who added the artifact to the export list,
- the artifact activity category,
- and the SHA-256, SHA-1, and MD5 hash for the sample with which the artifact is associated.
You can then filter
the generated CSV file based on this metadata.
For example,
a threat researcher who plans to circulate the CSV file across a
global IT department where regional offices might have different
security requirements could create regional labels to group artifacts.
She could then generate a CSV file on a daily or weekly basis, and
the regional IT departments can filter the list accordingly based
on the regional label (the labeled artifacts can then be added to
the appropriate regional block list).
- Generate a CSV file from the export list.
- Select Export List on the navigation pane.
- Select the artifacts you want to export.
- Click Export.
- Select Export Metadata and Export.The generated CSV file with metadata includes the following additional columns for each artifact row:Added Time,Section(this is the activity category during which WildFire observed the artifact),Label,SHA256,SHA1,MD5, andUser.