The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Integration with Trellix Intelligent Sandbox

Prev Next

The Trellix Intelligent Sandbox solution primarily consists of the Trellix Intelligent Sandbox appliance and its pre-installed software. The Trellix Intelligent Sandbox appliance is available in two models. The low-end model is the ATD-3000. The high-end model is the ATD-6000. You can deploy Trellix Intelligent Sandbox as a stand-alone appliance or integrate it with some of the other Trellix products. For complete information on Trellix Intelligent Sandbox, see the Trellix Intelligent Sandbox Product Guide.

Trellix Intelligent Sandbox has the added advantage of being an integrated solution. In addition to its own multi-level threat detection capabilities, its ability to seamlessly integrate with other Trellix security products, protects your network against malware and other Advanced Persistent Threats (APTs).

You can integrate Trellix Intelligent Sandbox with Trellix IPS. After you integrate, both the Sensor and the Manager communicate with Trellix Intelligent Sandbox separately to augment your defense against malware.

Outline of how this integration works— Based on how you have configured the corresponding Advanced Malware policy, the IPS Sensor detects a file download and sends a copy of the file to Trellix Intelligent Sandbox for analysis. If Trellix Intelligent Sandbox immediately detects the file to be a malware, the Sensor can block the download. The Manager displays the results of the analysis from Trellix Intelligent Sandbox.

If Trellix Intelligent Sandbox requires more time for analysis, the Sensor allows the file to be downloaded. If Trellix Intelligent Sandbox detects a malware after the file has been downloaded, it informs Trellix IPS, and you can use the Sensor to quarantine the host until it is cleaned and remediated. You can configure the Manager to update all the Sensors about this malicious file. Therefore, if that file is downloaded again anywhere in your network, your Sensors might be able to block it.

Note

The Sensor that is integrated with Trellix Intelligent Sandbox can be deployed in inline, tap, or SPAN mode. However, similar to other malware engines, response actions such as Block and Send TCP Reset might not have the desired effect since the file might have reached the target host.