- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Supported File Types for AV Inspection
Do we have a list of suppported file types the AV engine will inspect?
Solved! Go to Solution.
- Labels:
-
Threat Intelligence
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
This cookbook mainly covers compression formats for which it is almost updated. Only two changes required:
1. remove "starting with AV engine 5.6, yet to be released" as AV engine 5.6 has been official released
2. should Add CHM format which is supported since AV engine 6.0.7 which has not been official released yet.
But for all the supported file types. I think all possible malicious file types are support, some need AV engine deep paser like Windows PE, some are just covered by signatures like Power Shell script. So the following file types should be added:
*. Windows PE
*. MacOS Mach-O
* Linux ELF
*. Java Dex
*. HTML,
*. Javascript, VB script, etc
* .Net
Av engine team will maintain a supported file type list for references. I will also ask the cookbook writer for the required changes.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Hello Andres,
Check attached document.
Thanks,
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
The document is for compression/archive support. For regular files, like Windows PE files (32-bit, 64-bit), ELF (Linux, all bitness), Mach-O (Mac OS X), Scripts (JS, VB, Perl, HTML, CSS, BAT, Shell, XML, etc), Java class files, etc.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Forgot to mention two natively supported file formats. DEX (Android) and FLASH.
AV engine has native CPRL intructions to decode and do pattern match on various parts of the relevant files.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Hi David,
could you recommend the document where all supported files are listed?
I've found this Cookbook link, but information looks a bit outdated.
Regards, Aleksey
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
This cookbook mainly covers compression formats for which it is almost updated. Only two changes required:
1. remove "starting with AV engine 5.6, yet to be released" as AV engine 5.6 has been official released
2. should Add CHM format which is supported since AV engine 6.0.7 which has not been official released yet.
But for all the supported file types. I think all possible malicious file types are support, some need AV engine deep paser like Windows PE, some are just covered by signatures like Power Shell script. So the following file types should be added:
*. Windows PE
*. MacOS Mach-O
* Linux ELF
*. Java Dex
*. HTML,
*. Javascript, VB script, etc
* .Net
Av engine team will maintain a supported file type list for references. I will also ask the cookbook writer for the required changes.
