Read the Key findings card#
Work through what the analysers flagged as worth attention, and follow any row back to the tab that produced it.
The Key findings card on the Overview tab summarises everything the analyser thinks is worth your attention. Each finding is a clickable link that jumps you to the tab where it came from.
What a finding row shows#
Each row describes one finding.
A finding always has three parts.
- A short label describing what was found, for example
Embedded segments (2)or16 embedded file signature(s) detected. - An origin tab. Click the chevron to switch the centre column to that tab. The tab opens at the right place when possible.
- A category derived from the analyser that produced the finding.
Where findings come from#
Findings come from every analyser that ran for the file.
- The carving pipeline produces findings for embedded segments, suspicious entropy regions, and polyglots. They jump to the Carving tab.
- PE, ELF, Mach-O, and PDF parsers can flag anomalies, packers, suspicious sections, and structural oddities. They jump to the relevant format tab.
- Archive parsers (ZIP, 7z, TAR, CAB, ISO, MSI) can flag suspicious paths, encryption, or zip-bomb candidates.
- YARA matches do not appear here. They live in the YARA tab. The At a glance card summarises them as the first matched family.
When the card is empty#
A row reading No findings surfaced. means the analysers that ran for this file produced nothing they flagged. It does not mean the file is safe. It means there is nothing to triage at the level the analysers report.