Skip to content



Author: Joe Lazaro
License: AGPL-V3
Version: 1.0
Supported observables types:
- hash
- filename
Registration required: True
Subscription required: False
Free subscription: True
Third party service:


EchoTrail Insights takes a Windows filename or hash and provides several unique pieces of analytical context including prevalence & rank scores, process ancestry, behavioral analysis, and security analysis.


key API key
Default value if not configured N/A
Type of the configuration item string
The configuration item can contain multiple values False
Is required True

Templates samples for TheHive#

Sample long form report on a filename from a Windows system