Configure file analysis
File analysis enables you to specify files to be hashed with the SHA-256 hashing algorithm. File hashes that match a threat collection generate a detection, and file hash data can be queried in records.
ExtraHop recommends that you manage these settings from an ExtraHop console, which is the default configuration in RevealX 360. For RevealX Enterprise, sensors manage these settings by default. If you prefer to manage the settings on a console instead of a sensor, you can transfer management to a console.
Prerequisites
You must meet these requirements to view and configure file analysis on your ExtraHop system.
- You must have System and Access Administration privileges.
- You must have NDR and NPM module access.
- Your ExtraHop system must be connected to ExtraHop Cloud Services.
Configure a size limit for file filters
You can specify a size limit that applies globally to all file filters. Any file that exceeds this limit will not be hashed.
Create a file filter
You can create custom file filters that determine which files are hashed on the system. The ExtraHop Default filter is enabled by default. The default filter cannot be modified and applies to executable media type files, any protocol, any locality, and any file extension.
Note: | Enabling a large number of custom file filters might degrade system performance. |
Transfer management of file analysis settings
For RevealX 360, ExtraHop consoles manage file analysis settings by default. For RevealX Enterprise, ExtraHop sensors manage these settings.
Note: | Transferring management for these settings also transfers management for all shared settings. |
- Log in to the console or sensor that is currently managing file analysis settings through https://<extrahop-hostname-or-IP-address>.
- Click the System Settings icon and then click File Analysis.
-
Transfer management of file analysis to a different system.
Option Description Transfer from sensor to console - Click Transfer Management.
- From the Managing Console drop-down list, select a console name.
Transfer from console to sensor - Click N of N connected
sensors.
The Management Settings window displays a list of sensors that the console manages shared settings and a list of sensors that manage their own settings.
- Click the name of the sensor that you want to manage its own settings.
- Log in to the sensor.
- Click Transfer Management.
- From the Managing Console drop-down list, select Sensor Appliance - Self.
Thank you for your feedback. Can we contact you to ask follow up questions?