Submit for Sandbox Analysis Task

After identifying a suspicious file object, you can submit the object for analysis in the Sandbox Analysis app using context menus on the Trend Vision One console.

  1. After identifying the object that you want to collect, access the context or response menu and click Submit for Sandbox Analysis.

    The Submit to Sandbox for Analysis Task screen appears.

  2. (Optional) Specify a Description for the response or event.
  3. (Optional) Specify the arguments that are used when the sandbox runs the submitted file object.

    A maximum of 1,024 characters can be entered.

  4. Click Create.

    Trend Vision One creates the task and displays the current command status on the Response Management app.

  5. Monitor the task status.
    1. Open the Response Management app.
    2. (Optional) Locate the task using the Search field or by selecting Submit for Sandbox Analysis from the Action drop-down list.
    3. View the task status.
      • Pending approval () (if applicable): The automated response task was created on the Workbench app and is waiting for approval

      • Rejected () (if applicable): The automated response task created on the Workbench app was rejected

      • In progress... (): Trend Vision One sent the command to the managing server and is waiting for a response

      • Queued (): The managing server queued the command because the Security Agent was offline

      • Successful (): The managing server successfully received the command

      • Unsuccessful (): An error or time-out occurred when attempting to send the command to the managing server, the Security Agent is offline for more than 12 hours, or the command execution timed out

  6. Check the Sandbox Analysis by selecting Check Sandbox Analysis () to view the analysis result in the Sandbox Analysis app. For more information about the Sandbox Analysis app, see Sandbox Analysis