Skip to content

Feature Request: Notify user if Assemblyline has already seen a sample #77

Open
@ociappara

Description

@ociappara

Is your feature request related to a problem? Please describe.

Our analysts frequently encounter the issue of redundancy, submitting a malware sample to Assemblyline that has already been analysed. While the current system allows users to query and identify such instances, it is not proving to be an intuitive or streamlined process. As a result, our team often misses opportunities for collaboration and shared learning with analysts who have previously studied the same sample.

To address this issue, we propose an automatic alert system in Assemblyline similar to the functionality offered by VirusTotal. Upon submission of a sample, if Assemblyline recognizes the sample as one that has been analysed previously, it should immediately trigger a notification. This alert would inform the user about the sample's existing presence in the system.

Metadata

Metadata

Labels

assessWe still haven't decided if this will be worked on or notenhancementNew feature or requestuiui-frontend

Type

No type

Projects

No projects

Milestone

No milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions