High-level steps to configure malware analysis

Prev Next

This section provides the high-level steps on how to configure Intelligent Sandbox for malware analysis and reporting

  1. Set up the Intelligent Sandbox Appliance and ensure that it is up and running.

    • Based on your deployment option, ensure that the appliance has the required network connections. For example, if you integrate it withTrellix IPS, make sure the Sensor, Manager, and the Intelligent Sandbox Appliance are able to communicate with each other.

    • Make sure the required static analysis modules, such as the Gateway Anti-Malware Engine are up-to-date.

  2. Create the analyzer VMs and the VM profiles.

  3. Create the analyzer profiles that you need.

  4. To upload the resultsto an FTP server, configure it and have the details with you before you create the profiles for the corresponding users.

  5. Create the required user profiles.

  6. Log on to the Intelligent Sandbox web application using the credentials of a user you created and upload a sample file for analysis. This is to check if you have configured Intelligent Sandbox as required.

  7. In the Analysis Status page, monitor the status of the analysis.

  8. After the analysis is complete, view the report in the Analysis Results page.