Verdict distribution
Engine status
Recent activity
| File | Type | Size | SHA-256 | Verdict | Duration | Time |
|---|
New detection rule
Presets marked validated verify a checksum, which removes false positives.
New SIEM forwarder
Streams every event to an external collector in real time.
A malicious verdict is emitted as critical, a lockout as alert.
Events per transmission cycle.
Streaming begins from the present moment. Existing history is not replayed unless you rewind the stream position afterwards.
New ingestion source
The directory must be mounted into the scanning service before it can be collected.
Absolute path inside the scanning container. Mount the host directory in docker-compose.yml under both backend and worker.
Comma separated. Leave blank to accept every file type.
System and partial-transfer files are always excluded.
bytes
bytes
Caps how much is queued at once, so a large drop cannot overwhelm the pipeline.
seconds
24-hour time. Leave both blank to collect around the clock.
Consecutive checks showing an unchanged size before the file is accepted. This prevents collecting a file that is still being copied.
seconds
Must be outside the watched directory, or the same files would be collected repeatedly.
After saving, use Verify access to confirm the directory is mounted and writable before enabling collection.
New transfer destination
Credentials are encrypted before storage and are never displayed again.
Shown in transfer records and audit entries.
seconds
OpenSSH, RSA, ECDSA or Ed25519. Encrypted immediately on save.
Tokens:
{date} {year} {month} {day} {status} {verdict} {true_type}
Octal mode applied at the destination.
Malicious files are never eligible under any setting.
Backoff: 30s, 2m, 10m, 30m, hourly.
seconds
Tolerates a brief network blip.
After saving, use Verify & pin host key on the destination card. Transfers are refused until the host key has been pinned.