The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Advantages

Prev Next

The following are the advantages of integrating Trellix IPS with Trellix Intelligent Sandbox.

  • When a supported file is being downloaded into your network, it can be analyzed in depth using Trellix Intelligent Sandbox. This fortifies your already strong anti-malware defense with Trellix IPS.

  • Trellix Intelligent Sandbox is not an inline device. It can receive files from IPS Sensors for malware analysis. So, it is possible to deploy Trellix Intelligent Sandbox in such a way that you obtain the advantages of an inline anti-malware solution but without the associated drawbacks.

  • Trellix Intelligent Sandbox does not sniff or tap into your network traffic. It analyzes the files submitted to it for malware. This means that you can place the Trellix Intelligent Sandbox appliance anywhere in your network as long as it is reachable to all the integrated Trellix products. It is also possible for one Trellix Intelligent Sandbox appliance to cater to all such integrated products (assuming the number of files submitted is within the supported level). This design can make it a very cost-effective and scalable anti-malware solution.

  • Android is currently one of the top targets for malware developers. With this integration, the Android-based handheld devices on your network are also protected. You can dynamically analyze the files downloaded by your Android devices such as smartphones and tablets.

  • Files are concurrently analyzed by various engines. So, it is possible for known malware to be blocked in almost real time.

  • When Trellix Intelligent Sandbox dynamically analyzes a file, it selects the analyzer virtual machine that uses the same operating system and other applications as that of the target host. This is achieved through its integration with ePO - On-prem or through passive device profiling feature of Trellix IPS. This enables you to identify the exact impact on a targeted host, so that you can take the required remedial measures. This also means that Trellix Intelligent Sandbox executes the file only the required virtual machine, thereby preserving its resources for other files.

  • Consider a host downloaded a zero-day malware, but a Sensor that detected this file downloaded submitted it to Trellix Intelligent Sandbox. After a dynamic analysis, Trellix Intelligent Sandbox determines the file to be malicious. Based on how you have configured the Advanced Malware policy, it is possible for the Manager to add this malware to the block list of all the Sensors in your organization's network. This file also might be on the blacklist of Trellix Intelligent Sandbox. Thus, the chances of the same file re-entering your network is reduced.

  • Even the first time when a zero-day malware is downloaded, you can contain it by quarantining the affected hosts until they are cleaned and remediated.

  • You can view the disassembly listing of PE files. The rich reporting feature of Trellix Intelligent Sandbox is also now available for the files detected by your Sensors.