Fortinet white logo
Fortinet white logo

CLI reference

exec filetype-prefilter sniffer

exec filetype-prefilter sniffer

Use this command to set the file type to be processed in sniffer mode.

Syntax

execute filetype-prefilter sniffer [file-type-groups]

Variable

Description

<enter>

Click Enter to dump all file types.

<filetype group>

The following filetype groups are supported. :

  • Executables
  • PDF_documents
  • Office_documents
  • Web_pages>
  • Compressed_archives
  • Flash_files
  • Android_files
  • Mac_files
  • Linux_files
  • Others

If no file type group is specified all the file types will be processed.

File type group defintions

Executables

CLASS, JAR, AUTOITSCRIPT, E32IMAGE, GENSCRIPT, MSC, HLP, POWERSHELL, ISO, SIS, INF, SISX, EXE, VBS, BAT, UPX, FSG, ASPACK, PETITE, NSIS, AUTOIT, DLL, MSI, DOTNET, INNO, PYTHON

PDF_documents

PDF

Office_documents

VSDX, WORDBASIC, WORDML, ACCESS, XML, VBA, MSOFFICE, Hangul_Office, MSOFFICEX, OPENOFFICE, DOC, XLS, PPT, DOCX, XLSX, PPTX, RTF

Web_pages

PHP, HTML, JS ,IFRAME, HTA, CSS, LNK, WOFF

Compressed_archives

DAA, ZIP, TAR, GZIP, BZIP, BZIP2, RAR, LZH, LZW, ARJ, CAB, _7Z, XZ, EGG, KGB, Z, ACE, XAR

Flash_files

SWF

Android_files

DEX, APK

Mac_files

MACH_O, DMG

Linux_files

ELF, PERLSCRIPT, SHELLSCRIPT, CPIO, RPM

Others

ACTIVEMIME, MIME, BASE64, BINHEX ,UUE, HOSTS, FATMACH, TNEF, UNICODE, PYARCH, CHM, CRX, THMX, FLAC, XXE, OTF, EMF, GPGEML, REGISTRY, PFILE, CEF, PRC, JAD, COD, JPEG, GIF, TIFF, PNG, BMP, MPEG, MOV, MP3, WMA, WAV, AVI, RM, TOR, HIBUN, SLK

Example

execute filetype-prefilter sniffer Executables PDF_documents Office_documents 

Only the file types in Executables,PDF_documents and Office_documents groups will be processed.

exec filetype-prefilter sniffer

exec filetype-prefilter sniffer

Use this command to set the file type to be processed in sniffer mode.

Syntax

execute filetype-prefilter sniffer [file-type-groups]

Variable

Description

<enter>

Click Enter to dump all file types.

<filetype group>

The following filetype groups are supported. :

  • Executables
  • PDF_documents
  • Office_documents
  • Web_pages>
  • Compressed_archives
  • Flash_files
  • Android_files
  • Mac_files
  • Linux_files
  • Others

If no file type group is specified all the file types will be processed.

File type group defintions

Executables

CLASS, JAR, AUTOITSCRIPT, E32IMAGE, GENSCRIPT, MSC, HLP, POWERSHELL, ISO, SIS, INF, SISX, EXE, VBS, BAT, UPX, FSG, ASPACK, PETITE, NSIS, AUTOIT, DLL, MSI, DOTNET, INNO, PYTHON

PDF_documents

PDF

Office_documents

VSDX, WORDBASIC, WORDML, ACCESS, XML, VBA, MSOFFICE, Hangul_Office, MSOFFICEX, OPENOFFICE, DOC, XLS, PPT, DOCX, XLSX, PPTX, RTF

Web_pages

PHP, HTML, JS ,IFRAME, HTA, CSS, LNK, WOFF

Compressed_archives

DAA, ZIP, TAR, GZIP, BZIP, BZIP2, RAR, LZH, LZW, ARJ, CAB, _7Z, XZ, EGG, KGB, Z, ACE, XAR

Flash_files

SWF

Android_files

DEX, APK

Mac_files

MACH_O, DMG

Linux_files

ELF, PERLSCRIPT, SHELLSCRIPT, CPIO, RPM

Others

ACTIVEMIME, MIME, BASE64, BINHEX ,UUE, HOSTS, FATMACH, TNEF, UNICODE, PYARCH, CHM, CRX, THMX, FLAC, XXE, OTF, EMF, GPGEML, REGISTRY, PFILE, CEF, PRC, JAD, COD, JPEG, GIF, TIFF, PNG, BMP, MPEG, MOV, MP3, WMA, WAV, AVI, RM, TOR, HIBUN, SLK

Example

execute filetype-prefilter sniffer Executables PDF_documents Office_documents 

Only the file types in Executables,PDF_documents and Office_documents groups will be processed.