Analyzing Malware with the ThreatStream Sandbox
In this section:
Malware analysis can be a lengthy and resource-intensive process when done manually. Additionally, analyzing malware on your primary systems (that hold your software and data) can compromise them. Sandboxes provide a secluded environment to run malware and review the results without compromising your primary systems.
ThreatStream provides a hosted sandbox that allows you to automatically analyze malware (files or URLs) and generates detailed reports of the findings. You can use these reports to determine the severity and impact of a particular malware on your organization. Using a sandbox for threat analysis enables you to focus your efforts only on malware samples that will severely impact your organization, thus saving you time and resources.
When you upload a malware file or URL, you can select whether the results of detonation should be available to everyone (Anomali Community), accessible to your organization only (My Organization), or shared with Trusted Circles.
Observables discovered and found to be malicious or suspicious during detonation can be imported to ThreatStream.
In addition to making sandbox submissions from the Sandbox list view page, you can email submissions to a phishing mailbox configured by your organization to detonate submissions in the sandbox. For more information on configuring mailboxes, see Mailboxes for Receiving Observables.
Available Sandbox Services in ThreatStream
The following sandbox services are available to you:
| Sandbox Service | Active by Default | # of default detonations once activated |
|---|---|---|
| No | 2/day | |
| Joe Sandbox via an Individual Subscription | No | Per your contract with Joe Sandbox |
| PolySwarm via an Individual Subscription | No | Per your contract with PolySwarm |
| No | Per your contract with VMRay |