Xcitium Verdict Cloud
-
Verdict is a cloud-based file verdict service that subjects unknown files to a range of tests in order to identify those that are malicious.
-
Xcitium Client Security can automatically submit unknown files to Verdict for analysis. When the tests are complete, Verdict will award a trust verdict to the file.
-
You can view the verdicts at 'Security' > 'Endpoint Security' > 'Verdict'
See View list of Verdict Analyzed Files for more details.
-
Click 'Dashboards' > 'Dashboards' > 'Verdict' to view summary of all Verdict results.
Note: The Verdict that comes with the free version of Xcitium will only run automated tests on an unknown file. The Premium version also includes manual testing by Xcitium research technicians. Please contact your Xcitium account manager for more details. |
You can configure general Verdict settings and create an analysis schedule in the Verdict
component of a Windows profile.
Configure Verdict Settings
-
Click 'Assets' > 'Configuration Templates' > 'Profiles'
-
Open the Windows profile you want to work on
Click the 'Verdict' tab then 'Edit', if it has already been added to the profile
OR
Click 'Add Profile Section' > 'Verdict' if it hasn't yet been added
The 'Verdict' settings screen
opens:
Verdict Settings - Table of Parameters |
|
---|---|
Form Element |
Description |
Lookup and Submit Files with Verdict |
Choose this option if you want the files to be submitted to the cloud file lookup service |
Check Manual Analysis Interval (sec)* |
How often XCS should contact Verdict for the verdicts on files submitted for manual analysis. (Default=60) |
Check Auto Analysis Interval (sec)* |
How often XCS should contact Verdict for the verdicts on files submitted for automatic analysis. (Default=60) |
Submit for |
Choose the type of Verdict analysis.
|
Enable Auto Whitelisting if NO suspicious activities detected by Automatic and/or Human-Expert analysis |
Choose this option if you wish the files identified as harmless by Verdict to be added to your local whitelist. |
Do NOT lookup and submit files to Verdict if File Lookup Service returns error |
Choose this option, if you don't want Verdict file analysis in case file look up service (FLS) failed. |
Submit Metadata |
Choose this option if you wish the unknown file is to be submitted to Verdict, along with their metadata. Metadata gives information about the file source, author, date of creation and so forth. |
Choose when the unknown files are to be submitted. The options available are: Immediately - XCS uploads the file to Verdict as soon as it encounters an Unknown file Schedule Analysis - XCS accumulates the unknown files and uploads them as per the set schedule. Refer to Verdict Analysis Schedule about how to set analysis schedule. |
Fields marked * are mandatory.
-
The 'Verdict Premium License' link takes to Verdict signup page for a full subscription.
The Verdict allows you to create a schedule for XCS to upload unknown files.
-
Select 'Schedule Analysis' from the 'Submit When' drop-down.
-
To upload the unknown files daily choose 'Daily' from the drop-down at the top and set the time for upload in HH:MM format in the combo boxes under 'Time'.
-
To upload the unknown files once per week, choose 'Every Week' from the drop-down at the top. Choose the day of the week from the 'Day of Week' options and set the time for upload in HH:MM format in the combo boxes under 'Time'.
-
To upload the unknown files monthly, choose 'Every Month' from the drop-down at the top, choose the day of the month from the 'Day of month' options and set the time for upload in HH:MM format in the combo boxes under 'Time'.