You can enable IVX Cloud for sandboxing file samples.
Note
Intelligent Sandbox, IVX and IVX Cloud can all be enabled, and the file will be submitted to all services at the same time.
In ePO, select Policy Catalog → Threat Intelligence Exchange.
Click TIE Settings, then click Edit on My Default Policy Settings.
Select the Sandboxing → Enable IVX Cloud service.
Configure IVX Cloud by adding following information:
Primary API key and server details.
Polling settings (the default Interval is 1 minute, and the Timeout is 10 minutes).
The following additional configurations:
Option
Definition
Screenshot
Select checkbox to extract screenshots of screen activity during dynamic analysis, which can later be downloaded with the artifacts API.
Video
Select checkbox to extract video activity during dynamic analysis, which can later be downloaded with the artifacts API.
File extraction
Select checkbox to extract dropped files from Virtual Machine during dynamic analysis, which can later be downloaded with the artifacts API.
Memory dump
Select checkbox to extract memory dump files from Virtual Machine during dynamic analysis, which can later be downloaded with the artifacts API.
PCAP
Select checkbox to extract PCAP files from Virtual Machine during dynamic analysis, which can later be downloaded with the artifacts API.
Force analyze
Select checkbox to force submission for this file, even if it is found to be a duplicate.
Analysis mode
Set the analysis mode for submission (the default mode is Sandbox).
Filter the File Types to send to IVX Cloud.
Click Save.
IVX Cloud is configured successfully.