Telemetry allows Intelligent Sandbox to collect data about malware and Intelligent Sandbox Appliance.
The data contains useful information about threat trends and product feature usage. The data is retained for 6 months, then deleted. Metadata, such as summary of the threat trends and feature usage, are maintained indefinitely. Telemetry data is collected and aggregated in the USA, then stored with our research team in India.
Note
The data collected do not include personally identifiable information (PII) of the customer or end user.
Intelligent Sandbox captures these two categories of data.
Category definitions
Category | Definition |
|---|
Telemetry data thatIntelligent Sandbox uses for Intelligent Sandbox Appliance | Intelligent Sandbox collects telemetry data to: System data that Intelligent Sandbox collects includes: Serial number Software version System type System uptime Status of the network interfaces Whether Syslog is enabled Whether LDAP is enabled Whether is enabled Whether SNMP is enabled Whether proxy settings are configured Whether Load Balancing (LB) is enabled The role held by a node in an LB cluster Whether DXL is enabled Whether Trellix GTI is enabled Whether TAXII is enabled Whether Email Connector is enabled Number of Portable Executable (PE) samples submitted Number of Flash files submitted Number of Microsoft Word files submitted Number of PDF files submitted Number of files scanned by Gateway Anti-Malware Number of files scanned by Trellix GTI Number of files scanned by Anti-virus Number of files scanned by YARA Number of files analyzed by the sandbox Number of files submitted to the sandbox Number of files submitted by each default user Details of analyzer profile Details of VM profile Count of the number of samples of each severity level. List of the top 10 malware that is determined through the analysis Version of the Detection Package downloaded
|
Telemetry data for: | Labs require the analysis results from Intelligent Sandbox telemetry data to: Telemetry data contains information about the analyzed samples, and includes: Type of the sample Final severity of the sample Detected YARA rule IDs SHA-1 of sample SHA-256 of sample MD5 hash value of sample Intelligent Sandbox detection score Digital signature data from sample Parent metadata corresponding to dropped files Intelligent Sandbox product information Intelligent Sandbox analyzing option scores URL visited by file IPv4 address visited by file Product version that the sample belongs to Publisher name of the sample Product name that the sample belongs to File version of the sample, operating system name, and operating system version on which the file was found on
|