Key features

Prev Next

Trellix Intelligent Sandbox is available as an on-premises appliance or a virtual form factor. All form factors act as a shared resource between multiple solutions.

Intelligent Sandbox provides these features.

 

  • Detection of file downloads — Detects when a user tries to download a file from an external resource.

  • Analysis of the file for malware — Verifies if the file contains any known malware.

  • Block future downloads of the same file — Prevents future downloads of the file or its variants if the file is found to be malicious.

  • Identify and remediate affected hosts — Identifies the host that executed the malware, and also detects the hosts to which it has spread. Then, Intelligent Sandbox shares the report with your other security products. This allows you to quarantine the affected hosts until they are clean.

  • Local blacklist — Checks for a known malware using a local blacklist.

  • Cloud-lookups — Integrates with the Trellix Global Threat Intelligence to detect malware that has already been identified by organizations throughout the globe.

  • Emulation capabilities — Integrates with Trellix Gateway Anti-Malware Engine for emulation capabilities.

  • Signature-based detection — Includes the Trellix Anti-Malware Engine for signature-based detection.

  • Sandboxing capability (Dynamic analysis) — Analyzes the file by executing it in a virtual sandbox environment to determine whether the file is malicious.