You can enable IVX Cloud for sandboxing file samples.
Make sure DXL local broker is deployed and configured.
In ePO - SaaS, select → → .
Select Threat Intelligence Exchange - SaaS and click Edit to enable IVX Cloud service.
Configure IVX Cloud with the following information:
Enable the Bypass DXL Local Broker for file submissions to IVX Cloud option to submit files without a DXL local broker.
Note
Enabling the Bypass DXL Local Broker for file submissions to IVX Cloud hides the Polling settings, Additional configurations, and File types options.
API keys and server list details as https://feapi.marketplace.apps.fireeye.com.
Polling settings (the default Interval is 1 minute, and the Timeout is 10 minutes).
The following additional configurations:
Option
Definition
Screenshot
Select checkbox to extract screenshots of screen activity during dynamic analysis, which can later be downloaded with the artifacts API.
Video
Select checkbox to extract video activity during dynamic analysis, which can later be downloaded with the artifacts API.
File extraction
Select checkbox to extract dropped files from Virtual Machine during dynamic analysis, which can later be downloaded with the artifacts API.
Memory dump
Select checkbox to extract memory dump files from Virtual Machine during dynamic analysis, which can later be downloaded with the artifacts API.
PCAP
Select checkbox to extract PCAP files from Virtual Machine during dynamic analysis, which can later be downloaded with the artifacts API.
Force analyze
Select checkbox to force submission for this file, even if it is found to be a duplicate.
Analysis mode
Set the analysis mode for submission (the default mode is Sandbox).
Filter the file types that will be sent to IVX Cloud.
Click save.
IVX Cloud is configured successfully.
Note
For customers that utilize the below ePO - SaaS deployments, files requested to be analyzed by IVX Cloud are sent to an EU based datacentre for analysis. Non-malicious files are deleted once the sandboxing operation has been completed and a verdict determined. Files that are deemed to be malicious are retained, encrypted, and securely stored for research purposes.
ePO - SaaS: AP-South (IND001)
ePO - SaaS: AP-South (AU001)
Trellix Threat Intelligence Exchange - SaaS offers a new feature where IVX Cloud users can identify the source machine of a file sample. This feature requires Adaptive Threat Protection Update 17 to work. To do this, → → .