MD Core Sandbox Engine Features

MetaDefender Sandbox technology is available as part of an integration with MD Core. The integration is available with two different engine types: embedded and remote sandbox engine (with full reporting). The embedded engine is deployed with MD Core, similar to other engines (CDR/DLP). The remote engine requires a side-by-side installation of the full standalone sandbox platform.

FeatureEmbedded EngineRemote Engine
Installation OSWindows, LinuxUbuntu (Linux)
Archive handlingNo *Yes
File parsersYesYes
File certificate validationYesYes
Image text analysis (OCR)NoYes
Microsoft Office file emulationYesYes
Powershell script emulationNoYes
URL emulation (ML based phishing detection)NoYes
Fuzzy hash lookupYesYes
Google safe browsingNoYes
OPSWAT reputation lookupYesYes
YARA pattern matchingYesYes

Note: for a full list of engine features of the MetaDefender Sandbox standalone product, then visit here.

*: The embedded engine doesn't support archive types itself, but the MetaDefender Core archive engine is able extract the files and send them to the sandbox for analysis

Type to search, ESC to discard
Type to search, ESC to discard
Type to search, ESC to discard