{% block head %}{% endblock %}
{% block header %} {% endblock %}MultiScanner is a file scanning and analysis framework that automatically runs a suite of tools against file submissions.
This page lets you submit files to be scanned. Click on the "Advanced Options" button to set options for archive files and set metadata fields to be added to the scan results. If you have a directory of samples you wish to scan at once, we recommend zipping them and uploading the archive with the option to extract archives enabled. Alternatively you can use the REST API for bulk uploads.
This page displays a searchable list of samples that have been scanned. Clicking on one will take you to the most recent scan report for that file.
This page displays a searchable list of scan reports. In contrast to the Analyses page, this page shows all reports, not merely the most recent.
This page displays the results of a single scan. Some rows in the report can be expanded or collapsed to reveal more data by clicking on the row header or the "Expand" button. Shift-clicking will also expand or collapse all of it's child rows. The "Expand All" button will expand all rows at once.
Click on "Notes" to open a sidebar where analysts may enter notes or comments.
Samples are downloaded as password-protected ZIP files. The password is infected.
Reports can be searched from any page, with a few options. You can search Analyses to get the most recent scan per file, or search History to get all scans recorded for each file. Use the "Default" search type to have wildcards automatically appended to the beginning and end of your search term. Use the "Exact" search type to search automatically append quotes and search for the exact phrase. Finally, use the "Advanced" search type to search with the full power of Lucene query string syntax. Nothing will be automatically appended and you will need to escape any reserved characters yourself. When you click on one of the search results, the search term will be highlighted on the Report page.
MultiScanner is copyright The MITRE Corporation, licensed under the Mozilla Public License, version 2.0.