The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Terminologies

Prev Next

Being familiar with the following terminologies facilitates malware analysis while using Intelligent Sandbox.

  • Static analysis — When Intelligent Sandbox receives a supported file for analysis, it first performs static analysis of the file. The objective is to check if it is a known malware in the shortest possible time, and also to preserve the Intelligent Sandbox resources for dynamic analysis. For static analysis, Intelligent Sandbox uses the following resources.

    Note

    Static analysis sequence is following.

    1.Global Whitelist > 2.Local Blacklist > 3.Trellix GTI / Trellix Gateway Anti-Malware Engine / Trellix Anti-Malware Engine (These three resources are processed in tandem.)

    • Global Whitelist — This is the list of MD5/SHA-256 hash values of trusted files and VBA scripts embedded inside a Microsoft Office application, which need not be analyzed.

      The whitelist feature is disabled by default. To enable or disable it, use the setwhitelist command. Use the Global Whitelist page on the Manage tab to manage the entries in the whitelist. In a load-balancing scenario, after the cluster creation, you need to run whitelistMerge cluster command on the Active node to manually copy the Global Whitelist database of Active node onto Secondary/Backup nodes. This is only a one-time activity, after which the Whitelist database of Secondary/Backup nodes is automatically overwritten by that of Active node at 0000 hours on a daily basis.

      Note

      The default whitelist entries are not periodically updated. However, they might be updated when you upgrade the Intelligent Sandbox software. When you upgrade the Intelligent Sandbox software to build 3.4.8.190 and above, MD5 added into the whitelist will be merged into Global Whitelist.

      The products that submit files to Intelligent Sandbox do have the capability to perform custom whitelisting as well. This includes the Skyhigh Secure Web Gateway and the Trellix Intrusion Prevention System.

    • Local Blacklist — This is the list of MD5 hash values of known malware stored in the Intelligent Sandbox database. When Intelligent Sandbox detects a malware through its heuristic Trellix Gateway Anti-Malware engine or through dynamic analysis, it updates the local blacklist with the file's MD5 hash value. A file is added to this list automatically only when its malware severity as determined by Intelligent Sandbox is medium, high, or very high. There are commands to manage the entries in the blacklist.

    • Trellix GTI — This is a global threat correlation engine and intelligence base of global messaging and communication behavior, which enables the protection of the customers against both known and emerging electronic threats across all threat areas. The communication behavior includes the reputation, volume, and network traffic patterns. Intelligent Sandbox uses both the IP Reputation and File Reputation features of GTI.

      Note

      DNS must be configured for GTI to run.

      Note

      For File Reputation queries to succeed, make sure Intelligent Sandbox is able to communicate with tunnel.message.trustedsource.org over HTTPS (TCP/443). Intelligent Sandbox retrieves the URL updates from List.smartfilter.com over HTTP (TCP/80).

    • Gateway Anti-Malware — Trellix Gateway Anti-Malware Engine analyzes the behavior of web sites, web site code, and downloaded Web 2.0 content in real time to preemptively detect and block malicious web attacks. It protects businesses from modern blended attacks, including viruses, worms, adware, spyware, riskware, and other crimeware threats, without relying on virus signatures.

      Trellix Gateway Anti-Malware Engine is embedded within Intelligent Sandbox to provide real-time malware detection.

    • Custom Yara Scanner — Custom Yara Scanner is a set of YARA rules.

    • Anti-Malware — Trellix Anti-Malware Engine is embedded within Intelligent Sandbox. The DAT is updated automatically based on the network connectivity of Intelligent Sandbox.

      Static analysis also involves analysis through reverse engineering of the malicious code. This includes analyzing all the instructions and properties to identify the intended behaviors, which might not surface immediately. This also provides detailed malware classification information, widens the security cover, and can identify associated malware that leverages code re-use.

    Note

    By default, Intelligent Sandbox downloads the updates for Trellix Gateway Anti-Malware Engine and Trellix Anti-Malware Engine every 90 minutes. To manually update these files, use CLI command, update_avdat.

  • Dynamic Analysis — In this case, Intelligent Sandbox executes the file in a secure VM and monitors its behavior to check how malicious the file is. At the end of the analysis, it provides a detailed report as required by the user. Intelligent Sandbox does dynamic analysis after the static analysis is done. By default, if static analysis identifies the malware, Intelligent Sandbox does not perform dynamic analysis. However, you can configure Intelligent Sandbox to perform dynamic analysis regardless of the results from static analysis. You can also configure only dynamic analysis without static analysis. Dynamic analysis includes the disassembly listing feature of Intelligent Sandbox as well. This feature can generate the disassembly code of PE files for you to analyze the sample further.

    Note

    Dynamic analysis sequence is following.

    1.Global Whitelist > 2.Local Blacklist > 3.Trellix GTI / Trellix Gateway Anti-Malware Engine / Trellix Anti-Malware Engine (These three resources are processed in tandem.) > 4.Yara Scanner > 5. Dynamic Analysis

  • Analyzer VM — This is the virtual machine on the Intelligent Sandbox that is used for dynamic analysis. To create the analyzer VMs, you need to create the VMDK file with the required operating system and applications. Then, using SFTP, you import this file into the Intelligent Sandbox Appliance.

    Only the following operating systems are supported to create the analyzer VMs:

    • Microsoft Windows XP 32-bit Service Pack 2

    • Microsoft Windows XP 32-bit Service Pack 3

    • Microsoft Windows Server 2003 32-bit Service Pack 1

    • Microsoft Windows Server 2003 32-bit Service Pack 2

    • Microsoft Windows Server 2008 R2 Service Pack 1

    • Microsoft Windows 7 32-bit Service Pack 1

    • Microsoft Windows 7 64-bit Service Pack 1

    • Microsoft Windows 8.0 Pro 32-bit

    • Microsoft Windows 8.0 Pro 64-bit

    • Android 2.3 or 4.3 by default. You can upgrade it to Android 5.0.

    All of the above Windows operating systems can be in English, Chinese Simplified, Japanese, German, or Italian.

    You must create analyzer VMs for Windows. You can create different VMs based on your requirements. The number of analyzer VMs that you can create is limited only by the disk space of the Intelligent Sandbox Appliance. However, there is a limit as to how many of them can be used concurrently for analysis. The number of concurrent licenses that you specify also affects the number of concurrent instances for an analyzer VM.

  • VM profile — After you upload the VM image (.vmdk file) to Intelligent Sandbox, you associate each of them with a separate VM profile. A VM profile indicates what is installed in a VM image and the number of concurrent licenses associated with that VM image. Using the VM image and the information in the VM profile, Intelligent Sandbox creates the corresponding number of analyzer VMs. For example, if you specify that you have 10 licenses for Windows XP SP2 32-bit, then Intelligent Sandbox understands that it can create up to 10 concurrent VMs using the corresponding .vmdk file.

  • Analyzer profile — This defines how to analyze a file and what to report. In an analyzer profile, you configure the following:

    • VM profile

    • Analysis options

    • Reports you wish to see after the analysis

    • Password for zipped sample files

    • Maximum execution time for dynamic analysis

    You can create multiple analyzer profiles based on your requirements. For each Intelligent Sandbox user, you must specify a default analyzer profile. This is the analyzer profile that is used for all files uploaded by the user. Users who use the Intelligent Sandbox web application to manually upload files for analysis can choose a different analyzer profile at the time of file upload. The analyzer profile selected for a file always takes precedence over the default analyzer profile of the corresponding user.

    To dynamically analyze a file, the corresponding user must have the VM profile specified in the user's analyzer profile. This is how the user indicates the environment in which Intelligent Sandbox should execute the file. You can also specify a default Windows 32-bit and a 64-bit VM profile.

  • User — An Intelligent Sandbox user is one who has the required permissions to submit files to Intelligent Sandbox for analysis and view the results. In case of manual submission, a user could use the Intelligent Sandbox web application or an FTP client. In case of automatic submission, you integrate products, such as Trellix IPS or Skyhigh Secure Web Gateway with Intelligent Sandbox. Then when these products detect a file download, they automatically submit the file to Intelligent Sandbox before allowing the download to complete. So, for these products default user profiles are available in Intelligent Sandbox.

    For each user, you define the default analyzer profile, which, in turn, can contain the VM profile. If you use the Intelligent Sandbox for uploading files for analysis, you can override this default profile at the time of file submission. For other users, Intelligent Sandbox uses the default profiles.