Overview Integrations Release Notes Operational Guide MetaDefender Sandbox API Reference v1
Getting Started
Support
Operational Guide
1.9.3
Search this version
Operational Guide
Operational Guide
THREAT HUNTING AND SEARCH
Title
Message
Create new category
What is the title of your new category?
Edit page index title
What is the title of the page index?
Edit category
What is the new title of your category?
Edit link
What is the new title and URL of your link?
Similarity Search
Copy Markdown
Open in ChatGPT
Open in Claude
Portable Executable type
These features are carefully selected based on their ability to provide accurate and relevant results, and they are continuously updated to stay current with the latest malware trends and techniques.
Binary metadata
Certificates
Characteristic
Disassembly sections
Dotnet info
Header info
Extracted
Threat Indicators
| Field name | Type | Description |
|---|---|---|
| Language | String | What speaking language does the binary target |
| Entry point section name | String | Name of the section where the entry point of the PE resides. It’s a calculated value, based on the supplied entry point address & section details. |
| Pdb path | String | Path of the PDB file on the compiler machine |
| DetectItEasyInfo | String | Information that has been extracted using DetectitEasy |
| Malware config | String | Malware configuration refers to the settings and parameters within malicious software that dictate its behavior, |
| File size | Number | Size of the input file |
| Unix timestamp | Number | A timestamp showing when the file was compiled |
| Subsystem | Number | Defines whether the PE is made to be a Console or UI application |
| Section number | Number | Number of sections present in the PE |
| Resource number | Number | Number of resources present in the PE |
| Resources to file ratio | Number | Ratio between the size of the resources & the file itself |
| Digitally Signed | Boolean | Whether the digital signature is verified or not. |
| Packed | Boolean | Whether the input file is packed or not |
| Total exported functions | Number | Indicates the number of exported functions in a PE |
| Total imported functions | Number | Indicates the number of imported functions in a PE |
| Digital signature verification | String | Whether the digital signature is verified or not. |
Type to search, ESC to discard
Type to search, ESC to discard
Type to search, ESC to discard
Pdb guid
Resources
Rich Header Compiler Ids
Sections
Strings
Imports
Version info
| Field name | Type | Description |
|---|---|---|
| Pdb guid | String | GUID of the PDB associated with the binary |
Type to search, ESC to discard
Type to search, ESC to discard
Type to search, ESC to discard
Similarity Search Filters
In addition to advanced technology, Similarity Search provides multi filtering search parameters. This feature offers greater flexibility and ensures that users receive the most accurate and relevant results for their specific needs.
Query filters
Non Query filters
| Field name | Type | Possible values | Example | Description | Required |
|---|---|---|---|---|---|
| SHA-256 | String | Number | Yes | ||
| Submission data | Date | 2023-01-17T12:17:20.000Z | Number | Optional | |
| Final Verdict | String | MALICIOUS, LIKELY_MALICIOUS, INFORMATIONAL, SUSPICIOUS, BENIGN, UNKNOWN | MALICIOUS | Verdict of a file | Optional |
| Tags | String | peexe,xml | Tags of a file | Optional | |
| Threshold | Number | 1 to 100 any integer | Number | Similarity threshold 0% to 100% Higher score means higher similarity | Optional |
| Limit | Number | 1 to 100 any integer | Number | Number of returns | Optional |
Type to search, ESC to discard
Type to search, ESC to discard
Type to search, ESC to discard
Type to search, ESC to discard
Type to search, ESC to discard
Type to search, ESC to discard
Last updated on
Was this page helpful?
Next to read:
Similarity Search Settings (Additional Scan Steps)See the "Technical Datasheet" for a complete list of features: https://docs.opswat.com/filescan/datasheet/technical-datasheet
Discard Changes
Do you want to discard your current changes and overwrite with the template?
Archive Synced Block
Message
Create new Template
What is this template's title?
Delete Template
Message
