When ICAP clients send samples to Deep Discovery Analyzer for analysis, Deep Discovery Analyzer performs a pre-scan which compares samples received with known
existing threats using the following resources:
-
Advanced Threat Scan Engine (ATSE) for file scans
-
YARA rules
-
Suspicious objects and user-defined suspicious objects lists
-
Predictive Machine Learning engine
-
Web Reputation Services (WRS) for URL scans
-
Deep Discovery Analyzer cache
Depending on the result of the pre-scan, Deep Discovery Analyzer performs the following
actions.
Result
|
Action
|
||
If the sample is a known good file / URL
|
|
||
If the pre-scan result for the sample is unknown
|
|
||
If the sample matches a known malicious threat
|
|
![]() |
NoteTo view the ICAP Pre-scan tab on the
Submissions screen, enable the setting in
. This tab is hidden by default.For details, see ICAP Tab.
|