Project

General

Profile

Feature #84

Display Finding Content From ThreatPatterns

Added by Luke Murphey about 14 years ago. Updated over 13 years ago.

Status:
New
Priority:
Normal
Assignee:
-
Category:
Scan Engine
Target version:
-
Start date:
04/09/2010
Due date:
% Done:

0%


Description

Display the content that matched the threat pattern signature in the scan report. This makes it easy to identify the actual content that tripped the rule.

History

#1 Updated by Luke Murphey about 14 years ago

For this to work NSIA needs to do the following:

  • Store the start and offsets of the finding
  • Store the conten that was scanned
  • Provide a view to display the finding (something like a cross between a hex editor interface and a graphical diff)

Note that ThreatScript definitions don't currently report the start and end of the finding.

#2 Updated by Luke Murphey about 14 years ago

This feature has been requested by multiple users

#3 Updated by Luke Murphey over 13 years ago

  • Category set to Scan Engine

Also available in: Atom PDF