Skip to content

mpkondrashin/sandboxer

Folders and files

NameName
Last commit message
Last commit date

Latest commit

 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 

Repository files navigation

Sandboxer

Inspect objects using Trend Micro Vision One or Deep Discovery Analyzer sandbox

License: MIT

Features

Major Features

  • Inspected objects: Files and URLs.
  • Supported sandboxes: Vision One and Deep Discovery Analyzer.
  • Supported platforms: Windows and macOS.

Minor Features

  • Auto notification and download when a new version is released.
  • Store analysis results for two months (this is a configurable option).
  • Show system notifications when a malicious file is detected
  • Show Vision One sandbox quota
  • Support HTTP proxy server including basic and NTLM authentication

Sandboxer submissions window:

Installation

Installation and usage video:

Installation and usage

Download latest release for your platform, unpack the zip file and run setup.exe (for Windows) or SandboxerInstaller (for macOS).

Choose your sanbox type: Vision One or Deep Discovery Analyzer. Then press the "Next" button.

If you selected Vision One on the first step, then enter Token. Learn more about API Keys and Roles. If the correct Domain value is not detected automatically, choose it from the dropdown list.

If you selected Deep Discovery Analyzer on the first step, provide its IP/DNS address and API Key. If you are using a self-signed certificate, check TLS Errors Ignore.

Remove the checkbox if there is no need to run Sandboxer automatically. It will be launched automatically upon file submission.

Wait for the file copy process to finish.

Press "Quit" button.

Usage

To Submit File On macOS

Right-click on the file and choose Quick Actions -> Sandboxer

To Submit Files On Windows

Right-click on the file and choose Send To -> Sandboxer. Note that for the latest Windows, you will have to choose first "Show more options".

To Submit URL

Run Sandboxer, if it is not yet running, and pick from its system tray icon menu "Submit URL" item.

To Get Results

Pick from the Sandboxer system tray icon menu "Submissions" item. Right-click on the menu icon "⋮" and choose "Show Report" or "Investigation Package".

Bugs

Notifications

On Windows, if notifications are disabled not by the Sandboxer Options window, but by using Notification Center, then it is not possible to turn them back on.

New version update

When Sandboxer shows that a new version is available, but upon downloading it shows an error, it means that the user has to wait several minutes and try again.

Unregistration

If unregistration is not performed from the Options dialog and/or during uninstallation Deep Discovery Analyzer connection is not available, then Sandboxer will be kept on the Submitters list and the only option will be to remove it using Analyzer Web UI. After installing Sandboxer once more, it will just register one more submitter.

Install error

If during the files copy phase, you encounter some error, try to return to the previous install phase and try again.

Install crash

To make sure that your installation is completed, check the sandboxer_setup_wizard.log log file generated along the installer executable. The last line should contain the following: "... INFO G0001 Close Logging ...". If not, try to run the installer once more.

macOS dark theme

If macOS uses a dark theme, it will be hard to see some text on the UI

Boxer picture

Icon is taken from Dog icons created by Freepik - Flaticon