Basic Features

Step #1 - Open /home/sandbox/sandbox/transform.cfg in a text editor

Step #2 - Modify the configuration by adding or modifying the properties on this page

Step #3 - Save the file and restart the sandbox service

Second Stage Malware Detection

Enable file downloads to detect 2nd stage malware downloaded from the Internet

transform.cfg
Copy
Property nameDefault valueDescription
runFileDownloaderstrueMain switch to enable file downloads
runFileDownloaderDistributedTimeoutMs1 minuteExecution timeout
fileDownloaderMaxFileDownloads10Download limit, '0' means no limit.

Malware Config Extraction

Enable malware config extraction

transform.cfg
Copy
Property nameDefault valueDescription
malwareConfigExtractionEnabledtrueSwitch to enable / disable malware config extraction
malwareConfigExtractionMaxInputFileSize100 MBFile size limit

Certificate Extraction

Enable certificate extraction for executable files and PDF documents

transform.cfg
Copy
Property nameDefault valueDescription
extractCertificatestrueSwitch do enable / disable certificate extraction
osslExecutionTimeout30 secondsExecution timeout

YARA

Enable YARA rule matching

transform.cfg
Copy
Property nameDefault valueDescription
runYaraRulesOnInputFiletrueSwitch to enable / disable YARA rule matching
runYaraRulesOnExtractedFilestrueExecute YARA also on extracted files
yaraExecutionTimeout30 secondsExecution timeout
runYaraRulesOnInputFileMaxFileSizeInMb100 MBFile size limit, '0' means no limit

Image Text Extraction (OCR)

Enable text extraction from images

transform.cfg
Copy
Property nameDefault valueDescription
runTesseractOCRForImagestrueSwitch to enable / disable OCR
tesseractExecutionTimeout10 secondsExecution timeout
tesseractLimitPerTransform5Limit: number of images to process

QR Code Scan

Enable QR code scan for images

transform.cfg
Copy
Property nameDefault valueDescription
runQRCodeScanForImagestrueSwitch to enable / disable QR code scanning
qrCodeScanLimitPerTransform20Limit: number of images to process

Text Metrics

transform.cfg
Copy

Enable text metrics generation like entropy, average word size, etc.

Property nameDefault valueDescription
generateTextMetricstrueEnable / disable text metrics generation
generateTextMetricsNGramSize5Size of collected ngrams
generateTextMetricsIncludeTopNGrams20Number of considered ngrams

Visualization

Enable image rendering of input file (file preview pages)

transform.cfg
Copy
Property nameDefault valueDescription
runFileVisualizertrueSwitch to enable / disable visualization
runFileVisualizerDistributedTimeoutMs10 secondsExecution timeout
Type to search, ESC to discard
Type to search, ESC to discard
Type to search, ESC to discard