FireEye

FireEye

File server infection scanning and file quarantine solution "FireEye Malware File Storage Scanning"

FireEye Malware File Storage Scanning uses its own virtual execution engine MVX, which is equivalent to Network Security and Server Email, which are the de facto standards for targeted attack countermeasures, and analyzes files on servers to detect and isolate malware. am.

Malware File Storage Scanning Basic Operation

Analyze files with FireEye's proprietary virtual execution engine, MVX. Malware File Storage Scanning acts as a client to access and analyze file servers. Specify any directory to scan.

operating conditions

  • Target server supports CIFS/SMB/NFS
  • The path must pass to the analysis target directory
  • Requires user with Read/Write permissions when in isolation mode
  • Communicable from the management IP address

Two modes of operation

  • monitor mode
    A mode that analyzes only and identifies malicious files
    Do not make any changes to the file information in the file server
  • Quarantine mode
    Modes for parsing and “quarantining”
    After analysis, files determined to be malicious are quarantined in a folder of your choice.

File quarantine solution

FireEye Malware File Storage Scanning analyzes files uploaded to the file server in the information LAN, sorts them into Good/Bad/Unknown, moves the Good folder to the internal business LAN, and makes it available to users.