>
Bitdefender Sandbox Analyzer is a security solution that enhances an organization’s security posture against sophisticated or targeted attacks through advanced detection and reporting capabilities. Delivered as a virtual appliance, the solution can integrate into your existing security architecture or be combined with additional Bitdefender security layers. The solution can effortlessly scale up as your infrastructure evolves.
Combines in-house threat intelligence streams with proprietary machine learning and behavioral detection for maximum, real-time accuracy.
Prevention and detection are performed fully on-premises, with no files sent for scanning outside your network.
Integrates natively with Bitdefender technologies and through API’s with other security elements.
A next-gen sandbox solution, Bitdefender Sandbox Analyzer on-premises features state-of-the-art machine learning, neural networks and behavioral analytics that ensure quick and accurate containment.
Features a comprehensive and easy-to-use visualization chart, that delivers a complete view of each detection and its underlying context. It learns the threat behavior, provides a timeline display of the system changes and even a screenshot of the message or error the user views as it is infected – such as a ransomware note.
Bitdefender extends the range of file supported by the sandbox to make the solution effective against a wide range of attack vectors, like applications, document, archives, emails and scripts. Different detonation profiles allow the sandbox throughput to be managed by shifting resources to increase the capacity or to increase the sandbox accuracy.
The solution identifies suspicious files and automatically sends them for detonation by built-in network sensors, ICAP protocol support, and through the integration with GravityZone (directly from the endpoint agent or from the central quarantine). For increase efficiency the sandbox incorporates a mechanisms that eliminates redundant scanning.
Bitdefender Sandbox Analyzer On-Premises is built entirely on proprietary Bitdefender technologies an leverages Bitdefender Advanced Threat Intelligence so it is never out of date, and is constantly improved over time with new intelligence.
Multiple golden image support enables security teams to emulate different real-life configurations on the sandbox instances ensuring that any attack that may occur on your specific configurations or apps will be detected in advance.
Risk Analytics
Web Threat Protection
Content Control
Device Control
Patch Management (add-on)
Full Disk Encryption (add-on)
The on-premises sandbox integrates natively with GravityZone and, through API’s, ensures broad integration with third party security solutions. The integration into the security architecture automates the submission of files and enables automatic response.
Exploit Defense
Cloud Intelligence and Machine Learning algorithms
Behavior Monitoring
Network Attack
Firewall
Automatic
Ransomware Mitigation (new)
Ran as an VM appliance, virtually unlimited scalability can be achieved by increasing the number of sandbox instances while maintaining a centralized management of the entire sandbox network under the GravityZone console.
Fileless Attack Defense
HyperDetect Tunable Machine Learning
Cloud Sandbox Analyzer
Attack Visualization and Forensics
Early breach detection
Guided investigation and response options
- The networks corresponding with the 2 NICs must be isolated from one another
- The detonation network should be provided with Internet connectivity