Setting IVX Cloud for sandboxing

Prev Next

You can enable IVX Cloud for sandboxing file samples.

Make sure DXL local broker is deployed and configured.

  1. In ePO - SaaS, select MenuConfigurationSettings.

  2. Select Threat Intelligence Exchange - SaaS and click Edit to enable IVX Cloud service.

  3. Configure IVX Cloud with the following information:

    • Enable the Bypass DXL Local Broker for file submissions to IVX Cloud option to submit files without a DXL local broker.

      Note

      Enabling the Bypass DXL Local Broker for file submissions to IVX Cloud hides the Polling settings, Additional configurations, and File types options.

    • API keys and server list details as https://feapi.marketplace.apps.fireeye.com.

    • Polling settings (the default Interval is 1 minute, and the Timeout is 10 minutes).

    • The following additional configurations:

    Option

    Definition

    Screenshot

    Select checkbox to extract screenshots of screen activity during dynamic analysis, which can later be downloaded with the artifacts API.

    Video

    Select checkbox to extract video activity during dynamic analysis, which can later be downloaded with the artifacts API.

    File extraction

    Select checkbox to extract dropped files from Virtual Machine during dynamic analysis, which can later be downloaded with the artifacts API.

    Memory dump

    Select checkbox to extract memory dump files from Virtual Machine during dynamic analysis, which can later be downloaded with the artifacts API.

    PCAP

    Select checkbox to extract PCAP files from Virtual Machine during dynamic analysis, which can later be downloaded with the artifacts API.

    Force analyze

    Select checkbox to force submission for this file, even if it is found to be a duplicate.

    Analysis mode

    Set the analysis mode for submission (the default mode is Sandbox).

  4. Filter the file types that will be sent to IVX Cloud.

  5. Click save.

IVX Cloud is configured successfully.

Note

For customers that utilize the below ePO - SaaS deployments, files requested to be analyzed by IVX Cloud are sent to an EU based datacentre for analysis. Non-malicious files are deleted once the sandboxing operation has been completed and a verdict determined. Files that are deemed to be malicious are retained, encrypted, and securely stored for research purposes.

  • ePO - SaaS: AP-South (IND001)

  • ePO - SaaS: AP-South (AU001)

Trellix Threat Intelligence Exchange - SaaS offers a new feature where IVX Cloud users can identify the source machine of a file sample. This feature requires Adaptive Threat Protection Update 17 to work. To do this, login to IVX CloudOverviewAdditional Context.