<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Advisories Result Blob in API / CLI Discussion</title>
    <link>https://community.checkpoint.com/t5/API-CLI-Discussion/Advisories-Result-Blob/m-p/32622#M2003</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I'm using Threat Prevention API. I followed the API documentation which is shared &lt;A _jive_internal="true" href="https://community.checkpoint.com/docs/DOC-2109-sandblast-api-documentation"&gt;here&lt;/A&gt;.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;On the page 18, where Threat Emulation XML report structure is explained, there's a field called &lt;STRONG&gt;More&lt;/STRONG&gt; which holds some Base64 like encoded data. It says that it is "&lt;STRONG&gt;Advisories result blob&lt;/STRONG&gt;", yet I don't know how to decode it. It really looks like Base64 encoded, but I didn't get any meaningful data by decoding it.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;How can I decode it? Any ideas?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Wed, 20 Jun 2018 14:21:30 GMT</pubDate>
    <dc:creator>Ahmet_Sezgin_Du</dc:creator>
    <dc:date>2018-06-20T14:21:30Z</dc:date>
    <item>
      <title>Advisories Result Blob</title>
      <link>https://community.checkpoint.com/t5/API-CLI-Discussion/Advisories-Result-Blob/m-p/32622#M2003</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I'm using Threat Prevention API. I followed the API documentation which is shared &lt;A _jive_internal="true" href="https://community.checkpoint.com/docs/DOC-2109-sandblast-api-documentation"&gt;here&lt;/A&gt;.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;On the page 18, where Threat Emulation XML report structure is explained, there's a field called &lt;STRONG&gt;More&lt;/STRONG&gt; which holds some Base64 like encoded data. It says that it is "&lt;STRONG&gt;Advisories result blob&lt;/STRONG&gt;", yet I don't know how to decode it. It really looks like Base64 encoded, but I didn't get any meaningful data by decoding it.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;How can I decode it? Any ideas?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 20 Jun 2018 14:21:30 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/API-CLI-Discussion/Advisories-Result-Blob/m-p/32622#M2003</guid>
      <dc:creator>Ahmet_Sezgin_Du</dc:creator>
      <dc:date>2018-06-20T14:21:30Z</dc:date>
    </item>
    <item>
      <title>Re: Advisories Result Blob</title>
      <link>https://community.checkpoint.com/t5/API-CLI-Discussion/Advisories-Result-Blob/m-p/32623#M2004</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Moving this to the SandBlast API section.&lt;/P&gt;&lt;P&gt;I'll see if I can get some insight from the relevant parties in R&amp;amp;D.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 20 Jun 2018 22:53:52 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/API-CLI-Discussion/Advisories-Result-Blob/m-p/32623#M2004</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2018-06-20T22:53:52Z</dc:date>
    </item>
    <item>
      <title>Re: Advisories Result Blob</title>
      <link>https://community.checkpoint.com/t5/API-CLI-Discussion/Advisories-Result-Blob/m-p/32624#M2005</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The "more" section in the XML is used for internal engine data. some of the data is used for debugging, statistics, logs and other details on the internal engine operation.&amp;nbsp; It is not decrypt-able on purpose since it does not hold data that represent the detonation of the file.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&amp;nbsp;&lt;/P&gt;&lt;P&gt;Gil&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 21 Jun 2018 11:52:45 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/API-CLI-Discussion/Advisories-Result-Blob/m-p/32624#M2005</guid>
      <dc:creator>Gil_Geron</dc:creator>
      <dc:date>2018-06-21T11:52:45Z</dc:date>
    </item>
    <item>
      <title>Re: Advisories Result Blob</title>
      <link>https://community.checkpoint.com/t5/API-CLI-Discussion/Advisories-Result-Blob/m-p/32625#M2006</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks for clarifying.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 21 Jun 2018 12:14:01 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/API-CLI-Discussion/Advisories-Result-Blob/m-p/32625#M2006</guid>
      <dc:creator>Ahmet_Sezgin_Du</dc:creator>
      <dc:date>2018-06-21T12:14:01Z</dc:date>
    </item>
  </channel>
</rss>

