cancel
Showing results for 
Search instead for 
Did you mean: 
Create a Post

Advisories Result Blob

Hello,

I'm using Threat Prevention API. I followed the API documentation which is shared here.

On the page 18, where Threat Emulation XML report structure is explained, there's a field called More which holds some Base64 like encoded data. It says that it is "Advisories result blob", yet I don't know how to decode it. It really looks like Base64 encoded, but I didn't get any meaningful data by decoding it.

How can I decode it? Any ideas?

Thanks.

3 Replies
Admin
Admin

Re: Advisories Result Blob

Moving this to the SandBlast API section.

I'll see if I can get some insight from the relevant parties in R&D.

0 Kudos
Employee
Employee

Re: Advisories Result Blob

Hi, 

The "more" section in the XML is used for internal engine data. some of the data is used for debugging, statistics, logs and other details on the internal engine operation.  It is not decrypt-able on purpose since it does not hold data that represent the detonation of the file. 

Regards, 

Gil

Re: Advisories Result Blob

Thanks for clarifying.