Web address analysis is only available if at least one Windows execution environment is installed.
Before browsing in Kaspersky Research Sandbox, you must specify the web address and select advanced settings if necessary.
To browse a web address in Kaspersky Research Sandbox:
In the drop-down list, all installed execution environments are available. If you have successfully deployed custom execution environments, they are also displayed in the list of available environments in the Custom environments section.
To analyze FTP links, it is recommended to use Microsoft Windows 7 images. If you want to use a Microsoft Windows 10 image, during the image configuration process you need to install additional software that processes FTP links.
You can specify the execution time from 30 to 1800 seconds (30 minutes). By default, the Auto value is selected (1800 seconds when using VNC mode and 100 seconds without VNC).
The web address will only be browsed in the selected environment during the specified execution time. The specified time does not include the time required for analysis and displaying results.
You cannot edit this option if a network channel was specified during template deployment.
The Auto item is selected by default. For more details about channels, refer to Internet channel values.
The list of available regions can contain individual countries in regions through which the internet can be accessed.
The recommended file size is 5 MB. If the Suricata rule file size exceeds 16 MB, we recommend that you split it into several files (up to 5 MB in size) and upload them to the task sequentially.
The check box is selected by default.
HTTPS traffic decryption reduce malware detection probability.
If you select the VNC access check box, the following options become available:
Enabling this parameter requires additional free disk space to store object execution results.
This check box is cleared by default.
Please note that added Suricata rules file will not be removed. Use the button to remove the required rule file.
An entry describing results appears in the History table. You can start to analyze results when the process completes and the Status field becomes Completed.
If the previously specified internet channel is no longer available, the Auto item is selected by default.
If you open the web address again later, results may differ from those shown in the History table for the same web address because Kaspersky expert systems update information about objects in real time. Results depend on the threat landscape.
Starting web address browsing