MD Core Sandbox Engine Features

MetaDefender Sandbox technology is available as part of an integration with MD Core. The integration is available with two different engine types: embedded and remote sandbox engine (with full reporting). The embedded engine is deployed with MD Core, similar to other engines (CDR/DLP). The remote engine requires a side-by-side installation of the full standalone sandbox platform.

FeatureEmbedded EngineRemote Engine
MetaDefender Core: Installation OSWindows, LinuxWindows, Linux
MetaDefender Sandbox: Installation OSUbuntu (Linux)
File parsersYesYes
Second-stage file downloadsNoYes
File certificate validationYesYes
Image text analysis (OCR)NoYes
Microsoft Office file emulationYesYes
Powershell script emulationNoYes
URL emulation (ML based phishing detection)NoYes
Fuzzy hash lookupYesYes
Google safe browsingNoYes
OPSWAT reputation lookupYesYes
YARA pattern matchingYesYes

Note: for a full list of engine features of the MetaDefender Sandbox standalone product, then visit here.

Type to search, ESC to discard
Type to search, ESC to discard
Type to search, ESC to discard