000026858 - Why does an extracted file appear as *.raw.exe in RSA Security Analytics?

Document created by RSA Customer Support Employee on Jun 14, 2016Last modified by RSA Customer Support on Sep 27, 2019
Version 3Show Document
  • View in full screen mode

Article Content

Article Number000026858
Applies ToRSA Product Set: Security Analytics
RSA Product/Service Type: Investigation
RSA Version/Condition: 10.6.x
Platform: CentOS
O/S Version: EL6
IssueWhy does an extracted file appear as *.raw.exe in RSA Security Analytics?
Resolution

Extracting files from sessions via the RSA Security Analytics Investigation UI produces files with file name *.raw.exe, e.g. 33525512115-9-0.raw.exe.



This is because raw.exe is a placeholder name for when an exe is identified within a session but no discernible filename is present.



For instance, the data channel session of FTP would contain just the file transfer but not the file name (which would be in the control channel session).

Legacy Article IDa66555

Attachments

    Outcomes