All Apps and Add-ons

What are Hit and Misses in the Forensic investigator app?

vatsal1511
Explorer

What is the meaning of Hit and Misses in Forensic Investigator app?
Does Hit mean virus detected or virus detection missed?

Thanks

0 Karma
1 Solution

TonyLeeVT
Builder

Yes, the first three boxes at the top of the VirusTotal dashboard are the following:

Hits, Misses, and Total Engines. Hits mean that a scan engine found that hash or URL to be dirty. A miss means that a scan engine did not find the hash or URL to be dirty. Total engines should be the sum of the previous two numbers.

You can verify that information by looking at the VT Hit Details information below. That is a table that sorts hits to the top of the list.

Feel free to run the demo hash to see how it works: 57f222d8fbe0e290b4bf8eaa994ac641

Enjoy!

View solution in original post

TonyLeeVT
Builder

Yes, the first three boxes at the top of the VirusTotal dashboard are the following:

Hits, Misses, and Total Engines. Hits mean that a scan engine found that hash or URL to be dirty. A miss means that a scan engine did not find the hash or URL to be dirty. Total engines should be the sum of the previous two numbers.

You can verify that information by looking at the VT Hit Details information below. That is a table that sorts hits to the top of the list.

Feel free to run the demo hash to see how it works: 57f222d8fbe0e290b4bf8eaa994ac641

Enjoy!

vatsal1511
Explorer

Thanks @TonyLeeVT

0 Karma
Get Updates on the Splunk Community!

Threat Hunting Unlocked: How to Uplevel Your Threat Hunting With the PEAK Framework ...

WATCH NOWAs AI starts tackling low level alerts, it's more critical than ever to uplevel your threat hunting ...

Splunk APM: New Product Features + Community Office Hours Recap!

Howdy Splunk Community! Over the past few months, we’ve had a lot going on in the world of Splunk Application ...

Index This | Forward, I’m heavy; backward, I’m not. What am I?

April 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...