Define supported scan types

When a scanner supports a certain type of scan (such as URL, IP, file, or file hash value scanning), you must add them to the scanner record. Aside from pairing a scanner to a supported scan type, the scan type is responsible for providing the instantiation scripts that perform the scan for the given type. This is represented by two script fields, Integration factory script and Processor factory script, on the Supported scan type screen. Scan types for File, Hash, IP and URL are provided.

Before you begin

Role required: sn_ti.admin

Procedure

  1. Navigate to Threat Intelligence > Threat Scanning > Scan Types.
  2. Click New.
  3. Fill in the fields on the form, as appropriate.
    Table 1. Scan types
    Field Description
    Scan type name Provide a name for the scan type.
    Default scanner Select a default scanner from the list of supported scanners. When a user submits a malware scan request from the security incident catalog, and specifies this scan type, the default scanner for that type will be used.
    Scan type description Enter a description of the scan type.
  4. Click Submit.