Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Feedback to findings representation #1

Open
kam193 opened this issue Mar 8, 2025 · 2 comments
Open

Feedback to findings representation #1

kam193 opened this issue Mar 8, 2025 · 2 comments
Assignees
Labels
enhancement New feature or request

Comments

@kam193
Copy link

kam193 commented Mar 8, 2025

Hey! I have some feedback after using the service a few times 😄

The behavioural analysis output is very comprehensive, but as HybridAnalysis can create a lot of information, it also means, it's difficult to find what is actually important:

Image

I'd suggest sorting findings by the threat level or, which I think may be better, presenting each threat level in a separated section and with separated heuristic. In this way, the malicious behavious heuristic would present just the malicious results, not all. Like in this picture, the heuristic says it's something malicious, but it presents the informative insights as first:

Image

In addition, it would be great to see a link to the results in HybridAnalysis in the result section

Thanks!

@kam193 kam193 changed the title Feedback to finding representation Feedback to findings representation Mar 8, 2025
@boredchilada
Copy link
Owner

Hey! I have some feedback after using the service a few times 😄

The behavioural analysis output is very comprehensive, but as HybridAnalysis can create a lot of information, it also means, it's difficult to find what is actually important:

Image

I'd suggest sorting findings by the threat level or, which I think may be better, presenting each threat level in a separated section and with separated heuristic. In this way, the malicious behavious heuristic would present just the malicious results, not all. Like in this picture, the heuristic says it's something malicious, but it presents the informative insights as first:

Image

In addition, it would be great to see a link to the results in HybridAnalysis in the result section

Thanks!

Yeah will look into this and standardize it a little more !

Good chance I may make it a little simpler like the Joe sandbox one, and definitely having the link to the HA result would be helpful

@boredchilada boredchilada self-assigned this Mar 8, 2025
@boredchilada boredchilada added the enhancement New feature or request label Mar 8, 2025
@kam193
Copy link
Author

kam193 commented Mar 9, 2025

Great! When implementing URL, maybe you can have a look at CybercentreCanada/assemblyline#334 (comment) - apparently there is a way to make URLs clickable!

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
enhancement New feature or request
Projects
None yet
Development

No branches or pull requests

2 participants