Cortex-Analyzers icon indicating copy to clipboard operation
Cortex-Analyzers copied to clipboard

[Improvement] Joe Sandbox Analyzer should pull a more detailed report from the JoeSandbox

Open Passimist opened this issue 5 years ago • 0 comments

Feature description I noticed the JoeSandbox analyzers pull the "irjsonfixed" report from the sandbox. This report is a strongly reduced version of the full sandbox report. It also lacks very important information. For example if a a file (like a .PDF) is corrupt and could not be analyzed it will show "0/100 clean" in TheHive and not even the "full report" in Cortex tells me that the analysis has come to an end when the file could not be opened. Thats why I think the analyzer should parse its results from the "jsonfixed" report instead and display analysis errors in some way.

Passimist avatar Jul 27 '20 09:07 Passimist