This URL gets the executable information for given hash value.
Resource URL
GET /<nbaid>/endpointintelligence/<hash>/executableinformation? duration=<duration>
Request Parameters
Field Name | Description | Data Type | Mandatory |
|---|---|---|---|
| Duration
| String | No |
| Hash | String | Yes |
| NTBA monitors id | String | Yes |
Response Parameters
Following fields are returned if the request parameters are correct, otherwise error details are returned.
Field Name | Description | Data Type |
|---|---|---|
| List of endpoint executables | Array |
Details of EndpointExecutableList:
Field Name | Description | Data Type |
|---|---|---|
| Executable properties | Object |
| Heuristics data | Object |
| Process using this library | Object |
| Parent process | Object |
| Suspicious libraries | Object |
Details of properties:
Field Name | Description | Data Type |
|---|---|---|
| Executable hash | String |
| Binary type | String |
| Binary name | String |
| Product name | String |
| Product version | String |
| Overall malware confidence | String |
| EIA agent malware confidence | String |
| Classification | String |
| Classifier | String |
| Classified | String |
| File size | Long |
Details of heuristics:
Field Name | Description | Data Type |
|---|---|---|
| Digitally signed | String |
| Certificate status | String |
| Packed | String |
| Resource section | String |
| Smaller than 500 KB | String |
| Embedded UI | String |
| Obfuscated file extension | String |
| Recently modified | String |
| GTI reputation | String |
Details of parentProcesses:
Field Name | Description | Data Type |
|---|---|---|
| Hash value | String |
| Name | String |
Details of suspiciousLibraries and libraryProcesses:
Field Name | Description | Data Type |
|---|---|---|
| Hash value | String |
| Name | String |
| Malware confidence | String |
Example
Request
Response
{
"properties":
{"hash":"1aaaaaaaaaaaaaaaaaaaaaaaaaaaaa23",
"binaryType":"Process",
"binaryName":"abc.exe",
"productName":"",
"productVersion":"file_version",
"overallMalwareConfidence":"Medium",
"eiaAgentMalwareConfidence":"Medium",
"classification":"unclassified",
"classifier":"---","filesize":2566795},
"heuristics":{},
"suspiciousLibraries":[{
"hash":"1aaaaaaaaaaaaaaaaaaaaaaaaaaaaab1",
"name":"abc_dll.dll",
"malwareConfidence":"High"}]
}
Error Information
Following error codes are returned by this URL:
S.No | HTTP Error Code | SDK API errorId | SDK API errorMessage |
|---|---|---|---|
1 | 400 | 3601 | Invalid duration |
2 | 400 | 4901 | Invalid hash/failed retrieve |