kosa8 docs

Commands / kosa8 lab diff

kosa8 lab diff

Compare two detonation reports: files, network indicators, processes

Usage

kosa8 diff REPORT_A REPORT_B

Verifies both packages, then lists what each run did that the other did not: paths changed in the container, DNS names, HTTP requests, TLS names, mail, other connections and datagrams, and processes at the end (by command, not PID). The runs to compare are usually the same sample under one changed condition — another image, a longer timeout — or two forks of one snapshot.

This compares reports, not snapshots: a block-level diff of two snapshots' disks is not built yet (docs/design/malware-lab.md).

Options

FlagTypeWhat it doesDefault
--pubkeystringpublic key both reports must be signed with—