Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
Ahmet_Sezgin_Du
Explorer

Advisories Result Blob

Hello,

I'm using Threat Prevention API. I followed the API documentation which is shared here.

On the page 18, where Threat Emulation XML report structure is explained, there's a field called More which holds some Base64 like encoded data. It says that it is "Advisories result blob", yet I don't know how to decode it. It really looks like Base64 encoded, but I didn't get any meaningful data by decoding it.

How can I decode it? Any ideas?

Thanks.

3 Replies
PhoneBoy
Admin
Admin

Moving this to the SandBlast API section.

I'll see if I can get some insight from the relevant parties in R&D.

0 Kudos
Gil_Geron
Employee Alumnus
Employee Alumnus

Hi, 

The "more" section in the XML is used for internal engine data. some of the data is used for debugging, statistics, logs and other details on the internal engine operation.  It is not decrypt-able on purpose since it does not hold data that represent the detonation of the file. 

Regards, 

Gil

Ahmet_Sezgin_Du
Explorer

Thanks for clarifying.

Leaderboard

Epsum factorial non deposit quid pro quo hic escorol.

Upcoming Events

    CheckMates Events