Strelka Scanner Overview¶
Strelka is a scalable file analysis framework that allows for the rapid analysis of files through a distributed system of scanners. Each scanner within Strelka has a specific role, ranging from extracting simple file metadata to executing complex detections and analyses. This overview provides insights into the capabilities and functionalities of each scanner within the Strelka ecosystem.
Deployed Scanners¶
Scanner Name | IOC Support |
Image Thumbnails |
File Emission |
Tests Created |
Malware Scanner |
Extended Docs |
---|---|---|---|---|---|---|
ScanBatch | ||||||
ScanBmpEof | ||||||
ScanBzip2 | ||||||
ScanDmg | ||||||
ScanDocx | ||||||
ScanDonut | ||||||
ScanEmail | ||||||
ScanEncryptedDoc | ||||||
ScanEncryptedZip | ||||||
ScanEntropy | ||||||
ScanExiftool | ||||||
ScanFooter | ||||||
ScanGif | ||||||
ScanGzip | ||||||
ScanHash | ||||||
ScanHeader | ||||||
ScanHtml | ||||||
ScanIqy | ||||||
ScanIso | ||||||
ScanJarManifest | ||||||
ScanJavascript | ||||||
ScanJnlp | ||||||
ScanJpeg | ||||||
ScanJson | ||||||
ScanLibarchive | ||||||
ScanLnk | ||||||
ScanLsb | ||||||
ScanLzma | ||||||
ScanMacho | ||||||
ScanManifest | ||||||
ScanMsi | ||||||
ScanOcr | ||||||
ScanOle | ||||||
ScanOnenote | ||||||
ScanPcap | ||||||
ScanPdf | ||||||
ScanPe | ||||||
ScanPgp | ||||||
ScanPhp | ||||||
ScanPkcs7 | ||||||
ScanPlist | ||||||
ScanPngEof | ||||||
ScanQr | ||||||
ScanRar | ||||||
ScanRpm | ||||||
ScanRtf | ||||||
ScanSevenZip | ||||||
ScanSwf | ||||||
ScanTar | ||||||
ScanTlsh | ||||||
ScanTnef | ||||||
ScanTranscode | ||||||
ScanUdf | ||||||
ScanUpx | ||||||
ScanUrl | ||||||
ScanVb | ||||||
ScanVba | ||||||
ScanVhd | ||||||
ScanVsto | ||||||
ScanX509 | ||||||
ScanXl4ma | ||||||
ScanXml | ||||||
ScanYara | ||||||
ScanZip | ||||||
ScanZlib |
Not Deployed Scanners¶
Scanner Name | IOC Support |
Image Thumbnails |
File Emission |
Tests Created |
Malware Scanner |
Extended Docs |
---|---|---|---|---|---|---|
ScanAntiword | ||||||
ScanBase64 | ||||||
ScanBase64Pe | ||||||
ScanCcn | ||||||
ScanCuckoo | ||||||
ScanDelay | ||||||
ScanElf | ||||||
ScanException | ||||||
ScanFalconSandbox | ||||||
ScanIni | ||||||
ScanNf | ||||||
ScanSave | ||||||
ScanStrings |