pandora-analysis / pandora

Pandora is an analysis framework to discover if a file is suspicious and conveniently show the results
https://pandora.circl.lu/
GNU Affero General Public License v3.0
251 stars 37 forks source link

Give more details about 'Extractor' module when suspicious #735

Open FafnerKeyZee opened 16 hours ago

FafnerKeyZee commented 16 hours ago

Hello,

when a file in an archive is suspicious, the extrator only display a warning. It could be very nice to know the reason of the warning.

image image 2.png.zip

In the same way, iit could be the same for the Error message: (from your instance) https://pandora.circl.lu/analysis/04de18bc-70cd-4ecd-b544-f695309240be

BR,

Rafiot commented 15 hours ago

I need to see how we can do that, because there can be multiple reasons. Not sure we want to have them all listed in the parent.

FafnerKeyZee commented 8 hours ago

Maybe by adding that a least one file was malicious, suspicious, raise a warning ... we need to have an indication, not only a warning/alert