This command displays the file reputation query response for the md5 hash from the GTI server configured in the Manager.
Syntax:
filerep gti md5 <md5_hash>
Parameter | Description |
|---|---|
| Enter the md5 hash of the file for which you want the GTI response. |
Note
You can use this command to test connection to the GTI server configured in the Sensor and for debug purpose.
Sample Output:
IntruDebug#> filerep gti md5 83f6ac96f6e8188daaff089ed936cbde
DONE: https://nsp.rest.gti.trellix.com/1 => (total time 1.255940)
response: 0x7f810808
dirtiness: 0x8
malware score: very high
Applicable to:
NS-series and Virtual IPS Sensors