Note
You must have the Advanced Threat Protection license to use Advanced Heuristic analysis.
Attackers are increasingly using layers of obfuscation and packing to evade conventional detection and analysis tools. Netskope recursively unpacks files and extracts internal objects to make them fully available for analysis. You can use advanced statical analysis on binary files to deeply analyze binary file components without executing them.
The Netskope Advanced Heuristic engine:
- Detects signature-less malware.
- Conducts static analysis without file execution.
- Scans binary files to identify indicators of malicious activity.
- Analyzes files against 3,000+ threat indicators across a wide range of binary file types, including Windows, Mac OS, Linux, iOS, Android, and supports over 3,500 file format families.
- Decomposes, unpacks, and de-obfuscates files to extract all objects for analysis.
- Leverages its advanced engine to rapidly detect evasive, zero-day malware.
Viewing Advanced Heuristic Analysis
To view the Netskope advanced heuristics analysis:
-
Go to Incidents > Malware.
-
In the Files tab, click the File Name of the file you want to view advanced heuristics analysis.
-
Click Netskope Advanced Heuristics Analysis to see the following information:
-
File Details: Shows certificate, signer, issuer, algorithm, and container file information. You can also:
-
Click Total to see archive child sub-components and files.
-
Click See Malicious Files to see which of the sub-components and files are malicious.
-
-
Network References: Shows domain information.
-
Indicators: Shows activity of malicious behavior.
-
Key Capabilities: Shows what the malware is capable of doing.
-

