Configure security and performance options

Prev Next

To ensure that Intelligent Sandbox runs securely and efficiently, configure the Global Settings.

  1. Log on to the Intelligent Sandbox web interface.

  2. Click ManageTIS ConfigurationGlobal Settings.

  3. Configure the following settings.

    Option

    Definition

    Prevent unsupported file types

    When selected, prevents Sensors from sending unsupported file types to Intelligent Sandbox for analysis.

    Accept files based on extensions

    When selected, allows Intelligent Sandbox to accept the file based on the file extension, instead of only the file header, before it is sent for dynamic analysis.

    GTI lookup for links embedded inside PDF files

    When selected, allows Intelligent Sandbox to complete the Trellix GTI lookup of links that are embedded in PDF files during dynamic analysis.

    Generate STIX report

    When selected, allows Intelligent Sandbox to generate the STIX report, which displays the activities that malware has performed on the sandbox environment.

    MEG Wait-Time Threshold in Seconds

    Specifies the maximum wait time that Intelligent Sandbox uses to analyze samples from your configured secure gateway.

    X-Mode Maximum Time

    Specifies the maximum time that users can access the sandbox environment.

    Apply Custom Behavioral Rules

    When selected, allows you to use your own YARA rules to identify and classify malware based on the behavioral API logs.

    Apply Custom Memory Dump Rules

    When selected, allows you to use your own YARA rules to identify malware based on the memory dump logs.

    File Sizes

    Allows you to set the minimum and maximum file size of the supported file type. Click the minimum or maximum size of the respective file type to edit.

  4. Click Save.

    Note

    To return the settings to the default configuration, click Reset Settings to Default.