Sandbox Analysis

Products that can send samples to Deep Discovery Analyzer for sandbox analysis:

Note:

All samples display on the Deep Discovery Analyzer management console, on the Submissions screen (Virtual Analyzer > Submissions). Deep Discovery Analyzer administrators and investigators can also manually send samples from this screen.

  • Apex One as a Service

  • Apex One 2019

  • Deep Discovery Email Inspector 2.5 or later

  • Deep Discovery Inspector 3.7 or later

  • Deep Discovery Web Inspector 2.5 or later

  • ScanMail for Microsoft Exchange 11.0 or later

  • ScanMail for IBM Domino 5.6 SP1 Patch 1 HF4666 or later

  • InterScan Messaging Security Virtual Appliance (IMSVA) 8.2 SP2 or later

  • InterScan Messaging Security Suite (IMSS) for Windows 7.5 or later

  • InterScan Web Security Virtual Appliance (IWSVA) 6.0 or later

  • InterScan Web Security Suite (IWSS) 6.5

  • InterScan Messaging Security Suite (IMSS) for Linux 9.1

  • Deep Security 10.0 or later

  • Deep Edge 2.5 SP2 or later

  • OfficeScan XG or later

  • Trend Micro TippingPoint Security Management System 5.0 or later

  • Trend Micro Web Security 3.1 or later

On the management console of the integrating product, go to the appropriate screen (see the product documentation for details on which screen to access) and specify the following information:

  • API key. This is available on the Deep Discovery Analyzer management console, in Help > About.

  • Deep Discovery Analyzer IP address. If unsure of the IP address, check the URL used to access the Deep Discovery Analyzer management console. The IP address is part of the URL.

  • Deep Discovery Analyzer IPv4 or IPv6 virtual address. When using Deep Discovery Analyzer in a high availability configuration, the virtual IP address is used to provide integrating products with a fixed IP address for configuration. This is available on the Deep Discovery Analyzer management console, in Administration > System Settings > High Availability.

  • Deep Discovery Analyzer SSL port 443. This is not configurable.

Important:

If the Deep Discovery Analyzer API key changes after registering with the integrated product, remove Deep Discovery Analyzer from the integrated product and add it again.

Note:

Some integrating products require additional configuration to integrate with Deep Discovery Analyzer properly. See the product documentation for details.

(Optional) On the Deep Discovery Analyzer management console, review and modify the weight values of integrated products to adjust Virtual Analyzer resource allocation. For details, see Submitters.