Cortex-Analyzers
Cortex-Analyzers copied to clipboard
[Improvement] Joe Sandbox Analyzer should pull a more detailed report from the JoeSandbox
Feature description I noticed the JoeSandbox analyzers pull the "irjsonfixed" report from the sandbox. This report is a strongly reduced version of the full sandbox report. It also lacks very important information. For example if a a file (like a .PDF) is corrupt and could not be analyzed it will show "0/100 clean" in TheHive and not even the "full report" in Cortex tells me that the analysis has come to an end when the file could not be opened. Thats why I think the analyzer should parse its results from the "jsonfixed" report instead and display analysis errors in some way.