Mandiant, Inc.
System and method for triggering analysis of an object for malware in response to modification of that object
Last updated:
Abstract:
According to one embodiment, a system featuring one or more processors and memory that includes monitoring logic. During operation, the monitoring logic is configured to monitor for and detect a notification message that is directed to a destination other than the monitoring logic and identify an event associated with a change in state of a data store associated with the file system to occur. The notification message, at least in part, triggers a malware analysis to be conducted on an object associated with the state change event.
Status:
Grant
Type:
Utility
Filling date:
16 Nov 2018
Issue date:
22 Dec 2020