How it works

Prev Next

Intelligent Sandbox integrates with other Trellix and third-party products to provide you a multilayered defense mechanism against malware.

This workflow gives you a high-level overview of how Intelligent Sandbox works.

  1. A system tries to download a file with an embedded threat.

  2. The file is:

    1. Automatically redirected to the McAfee Web Gateway where it's compared to known threats. If the file is deemed suspicious, it is redirected to Intelligent Sandbox.

    2. Manually submitted for analysis to Intelligent Sandbox by the administrator.

  3. Once the file reaches Intelligent Sandbox, one or both of these occur:

    1. The file hash of the file is compared to the file hashes in Trellix GTI .

    2. The file is executed and observed in a sandbox to find if there is a threat enclosed.

  4. If a threat is found when the file is opened, the threat is reported to Trellix GTI and all other connected security products. This allows you and your security products to take preventive measures such as blocking the file or quarantining the affected hosts.

  5. If your Intelligent Sandbox is managed by ePO - On-prem, a notification of the threat is sent to ePO - On-prem and the administrator.

ATD_WorkFlow_Portal.png