{"id":33,"date":"2013-06-17T09:54:28","date_gmt":"2013-06-17T09:54:28","guid":{"rendered":"http:\/\/www.3lectrik.com\/normanshark\/?page_id=33"},"modified":"2013-06-18T07:52:57","modified_gmt":"2013-06-18T07:52:57","slug":"apis","status":"publish","type":"page","link":"https:\/\/www.3lectrik.com\/normanshark\/products-solutions\/technology\/apis\/","title":{"rendered":"APIs"},"content":{"rendered":"<h3>Application Programming Interface (API)<\/h3>\n<p>The Malware Analyzer G2 (MAG2) provides a powerful API which provides programmatic access to the solution\u2019s functionality and facilitates task automation and integration into a customer\u2019s existing security workflows.\u00a0 The API is the core interface underpinning the MAG2 solution, purpose-built to support numerous workflows and complex business processes.<\/p>\n<p>The MAG2 API is more comprehensive than its UI, as more complex and conditional processing can be accomplished programmatically than can be achieved manually by a user exercising a console.\u00a0 High-volume tasks can be automated through the API and analysis results can be routed to different downstream processes or to different recipients for further action \u2013 spanning various departments or skill levels \u2013 depending on the analysis outcomes.<\/p>\n<p>The API is RESTful, accessible via the HTTP protocol, and provides programmatic access to nearly every aspect of MAG2.\u00a0 This includes uploading files, creating tasks, and checking queue and disk levels, among others.\u00a0 The API is designed to match the usual malware analysis workflow, making it easy to upload samples, schedule various analysis tasks, check the status, and retrieve analysis results.\u00a0 It is open, versioned, and fully published, complete with examples of common programmatic workflow tasks, while ensuring full backward compatibility even as product capabilities continue to evolve.<\/p>\n<p><b>Industry standard reports<\/b> \u2013 MAG2 reports are accessible through the API in industry standard JSON format, while binary serialization is implemented using Google protocol buffers, another widely adopted industry standard.<\/p>\n<p><b>Real-time notification of task state changes<\/b> \u2013 The API supports logic to trigger events based on real-time state changes including when tasks are added to a queue, when they are processed, and when they are completed.\u00a0 Applications include creating dashboard views of local MAG2 status or larger <b>SIEM<\/b>-style statuses.\u00a0 Notifications can also be used to direct post-processing such as re-running any \u201cdropped files\u201d through the MAG2 analysis after the primary sample has been run.<\/p>\n<p><b>VirusTotal counts \u2013<\/b> The MAG2 API can also be used to retrieve VirusTotal counts, along with the specifics concerning which anti-virus vendors have previously detected the sample and how each one has classified it.<\/p>\n<p><b>PCAPs<\/b> \u2013 MAG2 saves full packet captures (PCAPs) of all network transactions relating to each sample analysis.\u00a0 PCAP inspection can help security analysts to identify malware calls to command and control servers, login credentials or commands used by the malware, URL redirects to malicious websites, subsequent malware downloads, and data that has been exfiltrated from a victimized organization.\u00a0 PCAPS can also be post-processed through traditional IDS systems to add a layer of context.<\/p>\n<p><b>Native resources<\/b> \u2013 Accessible through the API are task resources including PCAPs, dropped files, screen shots, and any content that a plugin is designed to save.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Application Programming Interface (API) The Malware Analyzer G2 (MAG2) provides a powerful API which provides programmatic access to the solution\u2019s functionality and facilitates task automation and integration into a customer\u2019s existing security workflows.\u00a0 The API is the core interface underpinning the MAG2 solution, purpose-built to support numerous workflows and complex business processes. The MAG2 API [&hellip;]<\/p>\n","protected":false},"author":15,"featured_media":0,"parent":25,"menu_order":0,"comment_status":"open","ping_status":"open","template":"","meta":{"footnotes":""},"class_list":["post-33","page","type-page","status-publish","hentry"],"jetpack_shortlink":"https:\/\/wp.me\/P5TlPb-x","jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/www.3lectrik.com\/normanshark\/wp-json\/wp\/v2\/pages\/33","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.3lectrik.com\/normanshark\/wp-json\/wp\/v2\/pages"}],"about":[{"href":"https:\/\/www.3lectrik.com\/normanshark\/wp-json\/wp\/v2\/types\/page"}],"author":[{"embeddable":true,"href":"https:\/\/www.3lectrik.com\/normanshark\/wp-json\/wp\/v2\/users\/15"}],"replies":[{"embeddable":true,"href":"https:\/\/www.3lectrik.com\/normanshark\/wp-json\/wp\/v2\/comments?post=33"}],"version-history":[{"count":2,"href":"https:\/\/www.3lectrik.com\/normanshark\/wp-json\/wp\/v2\/pages\/33\/revisions"}],"predecessor-version":[{"id":135,"href":"https:\/\/www.3lectrik.com\/normanshark\/wp-json\/wp\/v2\/pages\/33\/revisions\/135"}],"up":[{"embeddable":true,"href":"https:\/\/www.3lectrik.com\/normanshark\/wp-json\/wp\/v2\/pages\/25"}],"wp:attachment":[{"href":"https:\/\/www.3lectrik.com\/normanshark\/wp-json\/wp\/v2\/media?parent=33"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}