Sandbox
Use Sandbox to analyze potentially suspicious artifacts in isolated virtual environments. This helps you detect malicious behavior, extract indicators, and generate actionable threat intelligence without exposing live systems.
Before you Start
Sandbox availability and access vary by product. Ensure that the following product-specific requirements are met before you proceed:
Product | Requirement |
|---|---|
Intel Exchange | Your user group must have View Sandbox Records and Create Sandbox Records permissions enabled. |
Collaborate | Sandbox must be enabled for your organization. Contact your Collaborate administrator if Sandbox is not available. |
Steps
To perform a sandbox analysis, follow these steps:
Access Sandbox and select the Sandbox tab.
Submit using one of the following submission types:
File: Drag and drop a file or click Browse to select a file from your system for sandbox analysis. For more information on supported file formats and size limits, see Supported File Types and Size.
Note
ZIP files must contain only one file, and the extracted file must be within the supported file size limit.
Hash: Enter a valid SHA256 hash to submit an existing artifact for sandbox analysis. Analysis proceeds only if a file associated with the provided hash is available.
URL: Enter a valid URL or domain name for sandbox analysis.
QR Code: Drag and drop or click Browse to upload a file containing a QR code that resolves to a valid URL. The decoded URL is submitted for sandbox analysis. For more information on supported file formats and size limits, see Supported File Types and Size.
Note
If the uploaded file contains multiple QR codes that resolve to multiple URLs, each decoded URL is submitted separately and consumes quota individually.
Provide the required details for your submission. The available fields depend on the selected submission type.
Extract ZIP File: Select this option to extract and analyze the contents of an uploaded ZIP file instead of analyzing the ZIP file as a single artifact. By default, this checkbox is selected.
Note
This option is available only while uploading ZIP files.
Password (Optional): Enter the password if the uploaded ZIP file is password-protected. The password is used to extract the archive before analysis. If you select Extract ZIP File and do not provide a password or provide an incorrect password, the submission fails. For more information, see Frequently Asked Questions (FAQs).
URL: Displays the URL identified after resolving the submitted QR code file.
Note
This field is available only after you upload a QR code file.
Community: Displays the community for your submission. This is always Private, meaning only your organization can view it.
Sandbox Provider: Select one or more of the following providers to run the analysis in sandbox environments:
CAPE: Executes the submission in a Windows 10 virtual environment
win-10-build-19041.Triage: Offers multiple environments, including Windows, Linux, and Android.
Note
The environments available during analysis depend on the type of artifact submitted. If multiple providers are selected, a separate sandbox record is created for each provider.
Internet Access: Choose whether the sandbox environment has internet connectivity. When enabled (default), the sample can connect to external servers, fetch payloads, and trigger behaviors that require internet access. Disable it to run the analysis in a fully isolated environment.
Click Submit.
After submission, you can view the artifact in the Sandbox listing along with its analysis status. For more information, see View Sandbox Submissions.
Supported File Types and Size
Artifact Type | Supported Formats | Size |
|---|---|---|
Files | .dll, .upx, .exe, .msi, .chm, .hta, .iqy, .doc, .docx, .xls, .xlsx, .ppt, .pptx, .pub, .pub2016, .zip, .one, .mht, .hwp, .ich, .inp, .pdf, .rtf, .slk, .swf, .html, .bat, .ps1, .js, .jse, .vbe, .pl, .py, .vbs, .wsf, .apk, .dex, .jar, .lnk, .url, .jnlp, .reg, .xslt, .xps, .eml, .msg | 32 MB |
QR Code | .jpeg, .jpg, .png, .bmp, .gif, .tif, .tiff, .webp, .ppm, .pgm, .pbm, .pnm, .tga, .ico, .pcx, .dds, .sgi, .rgb, .im | 32 MB |