Know more about threats at ThreatExpert : http://www.threatexpert.com/
Updated: 28 Jul 2009 | 4 comments
ThreatExpert is an advanced automated threat analysis system designed to analyze and report the behavior of computer viruses, worms, trojans, adware, spyware, and other security-related risks in a fully automated mode.
In only a few minutes ThreatExpert can process a sample and generate a highly detailed threat report with the level of technical detail that matches or exceeds antivirus industry standards such as those normally found in online virus encyclopedias
http://www.threatexpert.com/
It would be great if we link this some with SEPM help . So that the customer can search and get information about the risk detected.
Comments
This can be very handy while
This can be very handy while analyzing loadpoint diagnostic logs and to determine if the file should be submitted for analysis or not.
Cheers,
Aniket
Response time is quicker as well
ThreatExpert will generally give a much quicker response for submissions as well since it is a public facing site unlike the Symantec submission page which requires a valid support account for submissions. This means there is a better chance that someone has already submitted your file so it will be identified quickly. This is also good for when you are submitting files to Symantec as we can reference what ThreatExpert detects the file as with what comes back from Security Response.
Kurt G.
Symantec Technical Specialist: Endpoint Security Advanced Team
Symantec Corporation www.symantec.com
Symantec Enterprise Support: (800) 342 0652
Another useful site.
Virustotal.com is another site that is very useful, especially after you have submitted the file to threatexpert and have an MD5 hash to search by.
It gives the results of 40-42 different antivirus products scan engines and the definition date each is using.
The only thing that I do not like about the virustotal site is that it is not owned by Symantec, while threatexpert is.
Good to know ThreatExpert is owned by Symantec.
and it looks very handy for getting MD5 hashes to use in SEP ADC.
Thanks.
Would you like to reply?
Login or Register to post your comment.