How does the Virtual Network Sensor determine whether to send a file to the sandbox?
With Send to sandbox enabled, the Virtual Network Sensor uses the following rules, in step-by-step order,
to determine whether to submit a file to the sandbox for analysis. If a file does
not match the criteria for any step, the Virtual Network Sensor does not submit the
file to the sandbox.
Rule
|
Criteria
|
Action
|
1
|
|
Submit file
|
2
|
|
Submit file
|
3
|
|
Submit file
|
4
|
|
Submit file
|
5
|
Detected activity matches one of the following rules:
|
Do not submit file
|
6
|
Heuristic detections, highly suspicious files
|
Submit file
|