MD Core Sandbox Engine Features

OPSWAT Filescan's Sandbox technology is available as part of an integration with MD Core. The integration is available with two different engine types: embedded and remote sandbox engine (with full reporting). The embedded engine is deployed with MD Core, similar to other engines (CDR/DLP). The remote engine requires a side-by-side installation of the full OPSWAT Filescan (Sandbox) platform.

FeatureEmbedded EngineRemote Engine
Installation OSWindows, LinuxUbuntu (Linux)
Archive handlingNoYes
File parsersYesYes
File certificate validationYesYes
Image text analysis (OCR)NoYes
Microsoft Office file emulationYesYes
Powershell script emulationNoYes
URL emulation (ML based phishing detection)NoYes
Fuzzy hash lookupYesYes
Google safe browsingNoYes
OPSWAT reputation lookupYesYes
YARA pattern matchingYesYes

Note: for a full list of engine features of the OPSWAT Filescan (Sandbox) standalone product, then visit here.

Type to search, ESC to discard
Type to search, ESC to discard
Type to search, ESC to discard