The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

How Trellix IPS - Intelligent Sandbox integration works

Prev Next

When you integrate Trellix IPS with Trellix Intelligent Sandbox, the Sensor initiates a communication channel with Trellix Intelligent Sandbox. This channel is open unless the Sensor is down, Trellix Intelligent Sandbox is down, or you disable the integration. By default, this communication channel is over SSL protocol. Trellix Intelligent Sandbox listens on port 8505 for such connections. You can also switch to TCP protocol for communication that Trellix Intelligent Sandbox listens on port 8506.

Note

If the communication channel between the Sensor and Trellix Intelligent Sandbox goes down, the system fault Sensor connectivity status with Trellix Intelligent Sandbox device is displayed.

The Manager accesses the RESTful APIs of Trellix Intelligent Sandbox for its communication. When a connection is required, the Manager establishes an HTTPS connection. Trellix Intelligent Sandbox listens on a fixed port number 443 for such connections.

The integration with Trellix Intelligent Sandbox enhances the Advance Malware feature of Trellix IPS. This enables you to detect even unknown malware. This integration takes advantage of the in-depth analyzing capabilities of Trellix Intelligent Sandbox including its ability to dynamically analyze and disassemble files.

Note

For Trellix Intelligent Sandbox, both the Manager and Sensor are like users. So, a user profile called nsp is pre-defined in Trellix Intelligent Sandbox. By default, the Manager uses the user name and password defined in this profile to establish its communication with Trellix Intelligent Sandbox. When the Sensor submits a file for analysis, Trellix Intelligent Sandbox uses the analyzer profile defined in the nsp to determine how to analyze the file and what to report back to the Manager. The Manager also allows different Sensors to have their own analyzer profile as per configured by the respective Sensor users.

When you integrate with Trellix Intelligent Sandbox, it is available as an additional malware engine for all the supported file types in the Advanced Malware Policies. You can select this engine along with any of the other malware engines except NTBA. Since Trellix Gateway Anti-Malware Engine is available in both Trellix Intelligent Sandbox and NTBA appliance, you can only select either of these engines for a file type.