cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 

Nsp analysis feature in advanced malware policy

Jump to solution
  • Hi everyone. 
  • i'm testing the nsp analysis feature in the advanced malware policy but it doesn't seem to work. can anyone give me a sample pdf file to test this feature. sensor detects pdf file but no alert because the file is medium confident
1 Solution

Accepted Solutions
fkazi04
Employee
Employee
Report Inappropriate Content
Message 4 of 4

Re: Nsp analysis feature in advanced malware policy

Jump to solution

Hello @Hiep_Nguyen 

If your traffic is passing via proxy, there are chances the proxy is sending a cached copy. In such scenario, you can clear cache and check. If it's direct internet, kindly clear browser cache and Sensor malware cache using command clearmalwarecache

Kindly contact support team if the files are still getting downloaded.

 

Regards,
Faizan

Was my reply helpful?
If you find this post useful, please give it a Kudos! l Also, Please don't forget to select "Accept as a solution" if this reply resolves your query!

View solution in original post

3 Replies
fkazi04
Employee
Employee
Report Inappropriate Content
Message 2 of 4

Re: Nsp analysis feature in advanced malware policy

Jump to solution

Hello @Hiep_Nguyen 

You can add hash of the pdf file in blacklist and then download the same file. The sensor should be able to block the file download. Regarding alert generation, you can change severity to medium and check if the alerts are triggered.

 

Regards,
Faizan

Was my reply helpful?
If you find this post useful, please give it a Kudos! l Also, Please don't forget to select "Accept as a solution" if this reply resolves your query!

Re: Nsp analysis feature in advanced malware policy

Jump to solution

you know, i tried with hash file and blacklisted it but it didn't work. Even I have downloaded it over and over again and the result is the same. 

fkazi04
Employee
Employee
Report Inappropriate Content
Message 4 of 4

Re: Nsp analysis feature in advanced malware policy

Jump to solution

Hello @Hiep_Nguyen 

If your traffic is passing via proxy, there are chances the proxy is sending a cached copy. In such scenario, you can clear cache and check. If it's direct internet, kindly clear browser cache and Sensor malware cache using command clearmalwarecache

Kindly contact support team if the files are still getting downloaded.

 

Regards,
Faizan

Was my reply helpful?
If you find this post useful, please give it a Kudos! l Also, Please don't forget to select "Accept as a solution" if this reply resolves your query!
You Deserve an Award
Don't forget, when your helpful posts earn a kudos or get accepted as a solution you can unlock perks and badges. Those aren't the only badges, either. How many can you collect? Click here to learn more.

Community Help Hub

    New to the forums or need help finding your way around the forums? There's a whole hub of community resources to help you.

  • Find Forum FAQs
  • Learn How to Earn Badges
  • Ask for Help
Go to Community Help

Join the Community

    Thousands of customers use our Community for peer-to-peer and expert product support. Enjoy these benefits with a free membership:

  • Get helpful solutions from product experts.
  • Stay connected to product conversations that matter to you.
  • Participate in product groups led by employees.
Join the Community
Join the Community