Skip to main content

73 docs tagged with "spectra-analyze"

View all tags

Advanced Search

Spectra Analyze Advanced Search delivers metadata search with 100+ keywords, Boolean operators, and cross-cloud discovery for malware identification.

Advanced Search API

Search for samples available on the local Spectra Analyze instance and Spectra Intelligence using the Advanced Search capabilities.

Alerts

Spectra Analyze Alerts provide real-time notifications for malware classification changes and analysis results with customizable subscriptions and delivery methods.

Analysis services

Spectra Analyze Analysis services integrate dynamic and static analysis with ReversingLabs Cloud Sandbox, Cuckoo, Joe Sandbox, and third-party sandboxes.

API Documentation

Spectra Analyze API Documentation enables REST API integration with automated workflows using authentication tokens for seamless appliance interaction.

Backup & Purge

Automated backup and purge operations for managing storage space and data retention.

Certificates

Manage Root CA certificates for Spectra Analyze and Spectra Detect appliances.

Classification Status API

Spectra Analyze Classification Status API retrieves threat classification, risk scores, and detection status for analyzed samples.

Configuration

System configuration settings and options for the Spectra Analyze appliance.

Connectors

Spectra Analyze connectors configuration for external system integration with SIEM and orchestration platforms.

Containers API

Get a list of all top-level containers from which the requested sample has been extracted during analysis.

Dashboard

Spectra Analyze Dashboard displays file submission statistics, malware trends, YARA matches, and threat intelligence analytics across configured time ranges.

Delete API

Spectra Analyze Delete API enables removal of malware samples and associated analysis data from the appliance with bulk operation support.

Deprecated Endpoints

Spectra Analyze deprecated API endpoints with migration guidance for updated versions and alternative implementations.

Discussion

The Discussion page displays the comments that have been added to a sample, either by the user who uploaded it or by other users.

Download API

Download samples from the appliance to local storage.

Dynamic Analysis Results

The Sample Details page shows any dynamic analysis service reports, if dynamic analysis services are configured on the appliance.

Extracted Files

A page that allows browsing through the entire hierarchy of files extracted from a sample.

Factory Reset

Perform factory reset operations and Solr index reset for troubleshooting.

File and URL Submissions

Spectra Analyze File and URL Submissions enable manual and automated analysis with sandbox integration, extraction, and multi-service threat detection.

File Preview / Visualization

The file preview window can be used to preview image samples, text documents and some script languages. It also provides Entropy and Structure tabs, and a HEX preview.

Flexible Intel Feed

Spectra Analyze Flexible Intel Feed configuration for STIX/TAXII threat intelligence integration with Spectra Intelligence.

Getting started with Spectra Analyze

Get started with Spectra Analyze: configure the Spectra Intelligence cloud connection, access the web interface, upload your first file for analysis, and interpret the results.

Graph Page [PREVIEW]

Spectra Analyze Graph visualizes relationships between malware samples, files, domains, and IPs for interactive threat connection exploration and analysis.

Integrations

Spectra Analyze service integrations configuration for dynamic analysis sandboxes, threat feeds, and analysis enhancement.

Layouts Editor

Spectra Analyze Layouts Editor for customizing sample summary displays with data blocks, sharing, and personalization options.

Licensing

Manage appliance licensing and license configuration.

Licensing API

Spectra Analyze Licensing API for generating machine IDs, uploading licenses, and monitoring license status for appliance management.

Network Threat Intelligence API

Spectra Analyze Network Threat Intelligence API provides reputation data and threat analysis for URLs, domains, and IP addresses.

Network Threat Intelligence Page

Spectra Analyze Network Threat Intelligence reveals URL, IP, and domain reputation with threat analysis, DOM inspection, and historical threat intelligence data.

PDF Report API

Download a PDF report of the analysis results for any sample on the appliance.

Processing Status API

Spectra Analyze Processing Status API monitors analysis progress for submitted files and URLs with real-time status updates.

Quota Usage Alerts

Spectra Analyze quota usage alerts configuration for email notifications on Spectra Intelligence usage and threshold monitoring.

Redundancy System

Configure and manage redundancy system settings for high availability.

Risk Tolerance [PREVIEW]

Spectra Analyze Risk Tolerance feature extends sample classification with additional analysis services for customized threat assessment.

Sample Details Page

The Sample Details page presents all the available information about a sample.

Sample Details Summary

The Report Summary page highlights the most interesting information about an analyzed sample.

Search & Submissions Page

Spectra Analyze Search & Submissions provides local and cloud file queries, bulk operations, filtered results, and network resource analysis tools.

Self-Service Registration

Spectra Analyze self-service registration setup with identity providers like Okta using SAML and OIDC integration.

Set Classification API

Override the classification of a sample, either locally or in the Spectra Intelligence cloud.

Setup and initial configuration

Spectra Analyze initial setup and configuration guide covering system requirements, deployment, licensing, and first-time appliance configuration.

Sources

The Sources page displays different types of sources for the selected sample, their time and date of retrieval, as well as any additional information.

Spectra Analyze

Spectra Analyze is a malware analysis solution for threat analysts and small teams. It combines static file decomposition, cloud threat intelligence from Spectra Intelligence, and collaborative workflows to accelerate threat detection and investigation.

Spectra Core - Static Analysis Results

Spectra Analyze Spectra Core results display static analysis reports with file information, behavior indicators, and risk assessment organized by section.

Submissions API

Spectra Analyze Submissions API enables programmatic submission of files and URLs for static analysis and malware detection.

System Status

Spectra Analyze System Status monitoring for appliance health, service status, resource utilization, and system log retrieval.

System Update

Manage system updates and software upgrades for the appliance.

Tags

Spectra Analyze Tags enable system and user-defined sample categorization with search filtering and bulk tagging for efficient malware organization.

Tags API

Create, delete or retrieve user tags for any sample on the appliance.

Threat Classification Sources

Threats can be classified by Spectra Core, Spectra Intelligence, dynamic analysis, or manually overridden. This page also contains a list of all possible classification reasons for a sample.

Timezone API

Spectra Analyze Timezone API for setting and querying system timezones to control appliance date and time display preferences.

Tokens

Spectra Analyze authentication token management for API access control and per-user key configuration and administration.

Troubleshooting

Troubleshoot common Spectra Analyze issues: file upload failures, classification problems, login errors, license warnings, and API errors.

User Roles

Spectra Analyze role-based access control for creating, editing, and managing custom user roles and permission assignments.

Users

Spectra Analyze user management for creating accounts, configuring access, and managing user directory and authentication settings.

YARA API

Retrieve YARA ruleset lists or their contents, create new rulesets, delete or update existing rulesets.

YARA Hunting

Spectra Analyze YARA Hunting enables custom ruleset creation, cloud synchronization, and malware detection with continuous and retroactive scanning.

YARA Repositories

Spectra Analyze YARA repositories management for rule synchronization, online sources, and custom GitHub configuration.

YARA Repository Management API

Managing YARA repositories and rulesets, including repository creation, update, deletion, job scheduling, and ruleset publishing.

YARA Retro API

Allows users to initiate or stop a local retro scan, manage cloud retro scans and check the YARA retro status on the appliance.

YARA Retroactive Hunting

Spectra Analyze YARA Retroactive Hunting scans historical samples and cloud data for rule matches, uncovering previously hidden malware detections.