Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
Ahmet_Sezgin_Du
Explorer

Advisories Result Blob

Hello,

I'm using Threat Prevention API. I followed the API documentation which is shared here.

On the page 18, where Threat Emulation XML report structure is explained, there's a field called More which holds some Base64 like encoded data. It says that it is "Advisories result blob", yet I don't know how to decode it. It really looks like Base64 encoded, but I didn't get any meaningful data by decoding it.

How can I decode it? Any ideas?

Thanks.

3 Replies
PhoneBoy
Admin
Admin

Moving this to the SandBlast API section.

I'll see if I can get some insight from the relevant parties in R&D.

0 Kudos
Gil_Geron
Employee Alumnus
Employee Alumnus

Hi, 

The "more" section in the XML is used for internal engine data. some of the data is used for debugging, statistics, logs and other details on the internal engine operation.  It is not decrypt-able on purpose since it does not hold data that represent the detonation of the file. 

Regards, 

Gil

Ahmet_Sezgin_Du
Explorer

Thanks for clarifying.

Leaderboard

Epsum factorial non deposit quid pro quo hic escorol.

Upcoming Events

    Tue 23 Apr 2024 @ 11:00 AM (EDT)

    East US: What's New in R82

    Thu 25 Apr 2024 @ 11:00 AM (SGT)

    APAC: CPX 2024 Recap

    Tue 30 Apr 2024 @ 03:00 PM (CDT)

    EMEA: CPX 2024 Recap

    Wed 01 May 2024 @ 02:00 PM (EDT)

    South US: HTTPS Inspection Best Practices

    Tue 23 Apr 2024 @ 11:00 AM (EDT)

    East US: What's New in R82

    Thu 25 Apr 2024 @ 11:00 AM (SGT)

    APAC: CPX 2024 Recap

    Tue 30 Apr 2024 @ 03:00 PM (CDT)

    EMEA: CPX 2024 Recap

    Wed 01 May 2024 @ 02:00 PM (EDT)

    South US: HTTPS Inspection Best Practices

    Thu 02 May 2024 @ 11:00 AM (SGT)

    APAC: What's new in R82
    CheckMates Events