When you submit a sample file for dynamic analysis, Intelligent Sandbox captures Windows events and WMI call traces. This includes application, system, security Windows events. Intelligent Sandbox allows you to search for suspicious strings and events through Windows event logs. Some samples do not generate event logs within the timeout period, therefore event logs are not displayed in the user interface. There is a possibility that only a few events will be captured, and the user interface will only display events that occurred within the timeout period.
To enable Windows event logs, go to Analyzer Profile and select Event Logs from Reports, Logs, and Artifacts.
Log on the Intelligent Sandbox web interface.
Select → → , then locate and open the file you want to submit for analysis.
Select the analyzer profile from the Analyzer Profile dropdown list.
Select the priority from the Submission Priority dropdown list.
Click Submit. The sample is uploaded to Intelligent Sandbox and is analyzed.
Navigate to → . The Analysis Reports page lists the status of the file.
Right-click the report
and select Event Logs.