The table below describes all available settings and the default values of all the settings that you can specify for the Sandbox Integration task.
Sandbox Integration task settings
|
Setting |
Description |
Value |
|---|---|---|
|
|
Enable and disable two-way authentication to further secure the connection to the Sandbox server. If client certificate validation is enabled on the Sandbox server side, enable the use of a client certificate and add a client certificate before starting the Sandbox Integration task. |
|
|
|
Maximum time to wait for a connection to the server in seconds. |
The default value is |
|
|
Maximum time to wait for a response from the server in seconds. |
The default value is |
|
|
Mode of sending an object to Sandbox to be scanned |
|
|
|
Quarantine file when a threat is detected. |
|
|
|
Perform a critical areas scan when a threat is detected. |
|
|
|
Create an IOC Scan task when a threat is detected. |
|
|
|
Quarantine the object when an indicator of compromise is detected. |
|
|
|
Perform a critical areas scan when an indicator of compromise is detected. |
|
|
|
Scopes for the IoC scan. |
|
|
|
IOC Scan task start mode. |
|
|
The [Servers.item_#] section contains the settings of the Sandbox server. |
||
|
|
Address of the server. IP address (IPv4 or IPv6) or fully qualified domain name (FQDN) of the integration server can be specified. |
Default value: |
|
|
Port for connecting to the server. |
The default value is |
|
The [SandboxTransferSettings] section contains settings for sending files for scanning in Sandbox. |
||
|
|
The maximum size of the scan request queue in megabytes. |
The default value is |