Commands / kosa8 lab diff
kosa8 lab diff
Compare two detonation reports: files, network indicators, processes
Usage
kosa8 diff REPORT_A REPORT_B
Verifies both packages, then lists what each run did that the other did not: paths changed in the container, DNS names, HTTP requests, TLS names, mail, other connections and datagrams, and processes at the end (by command, not PID). The runs to compare are usually the same sample under one changed condition — another image, a longer timeout — or two forks of one snapshot.
This compares reports, not snapshots: a block-level diff of two snapshots' disks is not built yet (docs/design/malware-lab.md).
Options
| Flag | Type | What it does | Default |
|---|---|---|---|
--pubkey | string | public key both reports must be signed with | — |