Mail & Sandbox Security Solutions
Run suspicious e-mail attachments and files in an isolated environment with FortiSandbox and DFX; clean the document with CDR before delivery.
Analyze Unknown Files Before They Reach the User
E-mail, web, file sharing systems and removable media are the core channels attackers use to deliver malicious content to organizations.
Traditional antivirus technologies provide an important security layer in detecting known threats. But zero-day malware, ransomware, phishing attachments, malicious Office documents, script-based attacks and sandbox evasion techniques have made more advanced analysis mechanisms necessary.
The core approach of sandbox technology is this:
Suspicious File → Isolated Environment → Static/Dynamic Analysis → Behavior Analysis → Verdict → Block / Quarantine / Allow
A suspicious file can thereby be examined in a secure and isolated environment before being run on the user's system.
What Is a Sandbox?
A sandbox is the advanced threat detection technology allowing unknown or suspicious files to be run in virtual environments isolated from the organization's real systems so their behavior is analyzed.
During analysis the file's behavior such as;
- Creating new processes
- Changing the registry
- Creating or deleting files
- Establishing network connections
- Carrying out DNS queries
- Reaching a Command & Control server
- Running PowerShell or scripts
- Attempting to establish persistence
can be tracked.
Static and Dynamic Analysis
In modern sandbox platforms two approaches can be used together.
Static analysis analyzes the file's structural characteristics without running it.
Dynamic analysis, in turn, observes its behavior by actually running the file in a controlled virtual environment.
Dynamic analysis offers a significant advantage particularly with unknown malware and zero-day threats.
Sandbox + E-Mail Security
Rather than an e-mail attachment being delivered to the user directly, it can be put through security layers:
Internet → Mail Security Gateway → Antivirus → Sandbox → Behavioral Analysis → Safe / Malicious → User
Should suspicious content be assessed as malicious, it can be blocked or quarantined before reaching the user.
CDR – Content Disarm & Reconstruction
One of the important technologies that can be assessed alongside a sandbox is Content Disarm & Reconstruction.
CDR's approach goes beyond trying to find the malicious content.
The file's active and potentially dangerous components are stripped out so a safe version can be rebuilt.
This approach can form an important additional security layer particularly in attacks carried out through;
PDF + Word + Excel + PowerPoint + other corporate documents
these formats.
Zero-Day Malware
Zero-day malware may not yet hold a known signature or IOC.
In this situation classic antivirus can miss the threat with the;
Hash unknown → No signature found
result.
A sandbox, by contrast, can look less at who the file is than at what it does.
Sandbox technologies therefore play an important role in detecting unknown threats.
Sandbox and MITRE ATT&CK
Advanced sandbox solutions can relate the malware behavior they observe to MITRE ATT&CK techniques.
For example;
Execution → Persistence → Defense Evasion → Credential Access → Command & Control
behavior of this kind can give the analyst clearer context about the nature of the attack.
Sandbox + SIEM + SOC
Carrying sandbox results into the SIEM allows the attack chain to be related to other security systems.
For example:
Mail Gateway → Suspicious attachment + Sandbox → Malicious verdict + EDR → Endpoint execution + Firewall → C2 connection
can be assessed by the SOC within a single attack chain.
Fortinet FortiSandbox
AI Supported Advanced Malware and Zero-Day Analysis
Fortinet FortiSandbox is Fortinet's advanced sandbox platform for detecting unknown and advanced threats.
FortiSandbox aims to detect zero-day threats, ransomware, malware and advanced attacks by using static and dynamic analysis, advanced AI/ML and FortiGuard Labs threat intelligence together.
Advanced AI and Machine Learning
In FortiSandbox's current architecture, purpose-built machine learning and AI models are used to speed up threat analysis and identify unknown attacks.
Assessing static and dynamic analysis results together with threat intelligence provides broader security context.
Fortinet Security Fabric Integration
One of FortiSandbox's important advantages is its integration with the Fortinet ecosystem.
FortiGate + FortiMail + FortiClient + FortiWeb + FortiSandbox + FortiAnalyzer / FortiSIEM
can be run together.
In Fortinet's current technical documentation, alongside the FortiGate, FortiMail, FortiClient EMS and FortiWeb integrations, different integration methods such as file submission over ICAP, network share and API are also supported.
E-Mail Security
Used together with FortiMail, suspicious e-mail attachments can be sent to FortiSandbox and analyzed before reaching the user.
Endpoint Security
Together with the FortiClient/Fortinet endpoint ecosystem, suspicious files can be sent for sandbox analysis and malicious content brought into endpoint security processes.
OT and Air-Gapped Environments
FortiSandbox is not aimed at standard IT environments alone. Current Fortinet documentation also holds deployment support for OT protocols and air-gapped network support. This capability is important in critical infrastructure and isolated network projects.
Deployment Options
FortiSandbox;
Hardware + Virtual Appliance + SaaS + PaaS
can be positioned with these options. Different models can thereby be applied according to the organization's data sovereignty, performance and architecture requirements.
Who Is FortiSandbox Suitable For?
It forms a strong alternative particularly at organizations using the Fortinet Security Fabric, wanting advanced malware analysis, holding high-volume file traffic, running a SOC operation or needing zero-day protection in IT/OT environments.
DFX Malware Mitigation Sandbox
AI Supported Sandbox, CDR and Multi-Vector Analysis
DFX Malware Mitigation Sandbox is an advanced sandbox platform running suspicious files in isolated virtual environments to analyze malicious behavior and aiming to neutralize threats.
DFX's notable side is that it does not limit sandbox analysis to e-mail attachments alone.
The platform can carry out central analysis by accepting files from different attack vectors such as;
E-Mail Attachments + Network Files + Hardware / USB + Web Documents
simultaneously.
Isolated Virtual Execution
Suspicious files are run in virtual environments separated from the organization's real systems.
Through purpose-built VM profiles, DFX aims to trigger evasive malware by imitating real user behavior and to analyze its behavior.
Advanced AI Scan
In DFX's advanced analysis layer;
AI Behavioral Categorization + YARA + MITRE ATT&CK
are used together.
The aim is thereby to assess suspicious behavior without relying on known malware signatures alone.
Content Disarm & Reconstruction
One of DFX's important differentiators is that it brings the CDR – Content Disarm & Reconstruction capability into the sandbox approach.
The active or risky components inside a suspicious document are cleaned so safe content can be delivered to the user.
This approach:
Detect → Analyze → Disarm → Reconstruct → Deliver
can go beyond the classic "block it if it is malicious" model in this way.
Microsoft Exchange Integration
DFX Malware Mitigation Sandbox can work integrated with Microsoft Exchange.
Attachments such as PDF or Office documents in incoming e-mail can be analyzed in a secure virtual environment and assessed before delivery to the user.
ICAP Integration
Thanks to ICAP support, the sandbox can be integrated with different security gateway and file transfer architectures.
This capability makes it easier to position DFX not merely as an e-mail sandbox but as a corporate file security component.
Network Share Security
Files moving over a network share being brought into automated analysis provides an additional security layer particularly at organizations holding shared file areas.
USB and Critical Infrastructure Security
Removable media security also stands out separately in the DFX ecosystem. DFX Media Transfer Station aims to make data transfer into sensitive networks secure by putting removable media such as USB through anti-malware, sandbox and CDR processes.
This approach can be an important differentiator particularly for;
Defence Industry + OT/ICS + SCADA + Closed Networks + Critical Infrastructure
these estates.
Detailed Reports & Audit
As a result of its analysis, DFX offers detailed reporting on file and process activity along with network behavior. Its Threat Intelligence layer is also used to relate IOC and hash data to real threat context.
Who Is DFX Suitable For?
It can be positioned as a strong alternative particularly for;
Critical infrastructure, the defence industry, closed networks, OT environments, organizations carrying out sensitive file transfer and organizations wanting to use sandbox and CDR technology together
these estates.
FortiSandbox or DFX Malware Mitigation Sandbox?
It is more accurate not to describe the two products here as direct copies of one another.
FortiSandbox
Fortinet Security Fabric + FortiGate + FortiMail + FortiClient + FortiWeb + AI/ML Sandbox + IT/OT + SOC
stands out in projects where this ecosystem matters.
DFX Malware Mitigation Sandbox
Sandbox + CDR + ICAP + Exchange + Network Share + USB/File Security + Critical Infrastructure
differentiates itself in projects where this approach matters.
The SecureSys Mail & Sandbox Approach
At SecureSys, in sandbox projects we can address not merely product deployment but the;
Attack Vector Analysis → Determining Mail/File Flows → Product Selection → POC → Sandbox Integration → Mail Gateway Integration → ICAP / File Transfer Integration → CDR Policies → SIEM/SOC Integration → Incident Response
processes together.
Advanced Malware and Zero-Day Protection with Sandbox Solutions
Traditional antivirus, firewall and e-mail security systems continue to be core components of corporate cyber security. Today, however, attackers use continuously changing malware samples, obfuscation techniques, encrypted payloads, malicious documents and previously unseen attack methods so they can evade security systems.
It is therefore important that organizations make advanced malware analysis and sandbox security technologies part of their security architecture.
Sandbox solutions analyze the behavior of suspicious files and content by running them in controlled environments isolated from real user systems.
The aim is thereby to detect different threats such as;
Known Malware + Unknown Malware + Zero-Day + Ransomware + Malicious Document + Phishing Attachment + Script + Exploit
and similar attacks.
With the Fortinet FortiSandbox and DFX Malware Mitigation Sandbox technologies, SecureSys raises organizations' security level against the advanced threats in their e-mail, web, network, file transfer and critical infrastructure.
What Is a Malware Sandbox?
A malware sandbox is the cyber security technology providing for suspicious files to be run in a secure and isolated analysis environment so their malicious behavior is detected.
A file's hash not being present in known malware databases does not mean the file is safe.
Particularly with newly created malware samples, no antivirus signature may exist yet.
At this point a sandbox analyzes not merely the file's identity but its behavior.
If the file carries out the;
Word → PowerShell → Encoded Command → Payload Download → Registry Persistence → Command & Control
behavior after running, for example, the sandbox can assess the file as a potential attack.
What Is an E-Mail Sandbox?
E-mail sandbox technology provides for the suspicious files in incoming or outgoing e-mail to be analyzed in an isolated environment before reaching the user.
Particularly;
- Microsoft Word
- Excel
- PowerPoint
- ZIP
- Executable
- Script
- Archive
files can be used by attackers to carry malicious content.
A typical E-Mail Sandbox architecture:
Internet → Secure Email Gateway → Antivirus / Reputation → Sandbox → Behavioral Analysis → Verdict → Mailbox
can be built in this way.
Should the file be assessed as malicious, the e-mail can be quarantined or blocked according to the organization's security policy.
What Is Zero-Day Sandbox Protection?
Zero-day attacks can exploit threats not yet known to the vendor or for which no security signature has been built.
A signature-based security approach alone may therefore not be enough against zero-day attacks.
Sandbox technology helps detect unknown threats by bringing;
Behavior Instead of Signature
this analysis into play.
This capability makes sandbox systems one of the important components of Advanced Threat Protection – ATP architecture.
Advanced Threat Protection – ATP
Advanced Threat Protection means more than one security technology being used together to detect advanced and targeted attacks.
A typical ATP architecture;
Antivirus + Reputation + Threat Intelligence + Static Analysis + Dynamic Analysis + Machine Learning + Sandbox + CDR
can consist of these components.
The aim is to put threats through different analysis layers rather than depending on a single security engine.
What Is the Difference Between a Sandbox and Antivirus?
Antivirus and sandbox are not alternatives to one another.
Antivirus is used particularly for detecting known threats quickly.
A sandbox, in turn, focuses on the unknown and suspicious files requiring deeper analysis.
Antivirus: "Have we seen this file as malicious before?"
Sandbox: "What does this file do when it runs?"
In an advanced security architecture the two technologies can therefore be used together.
What Is the Difference Between a Sandbox and EDR?
EDR and sandbox work at different security layers.
A sandbox focuses on analyzing suspicious content before it reaches or runs on the user's system.
EDR monitors the activity taking place on the real endpoint continuously.
For example, the;
Mail → Sandbox → Endpoint → EDR
architecture can be applied.
While the sandbox tries to stop the attack before it reaches the user, EDR detects the attack activity taking place on the endpoint.
What Is the Difference Between a Sandbox and CDR?
Sandbox and CDR are two different security approaches completing one another.
Sandbox: Analyzes whether the file is malicious.
CDR – Content Disarm & Reconstruction: Tries to build a safe file by cleaning the potentially risky active content inside the file.
For example:
Original Word Document ↓ CDR ↓ Macro / Active Content Removal ↓ Reconstructed Document ↓ User
this approach can be applied.
Particularly in document security, therefore;
Sandbox + CDR
together can form a strong security layer.
Which Files Can a Sandbox Analyze?
Depending on the product and licence model, different file types can be analyzed.
Among these can be different content such as;
- DOC / DOCX
- XLS / XLSX
- PPT / PPTX
- EXE
- DLL
- ZIP
- RAR
- JavaScript
- PowerShell
- Script
- URL
- HTML
and similar formats.
Because supported file formats can vary by product and version, the vendor's current technical matrix should be checked before the project.
How Does a Sandbox Work?
A typical sandbox analysis process consists of the following stages.
1. File Submission
The suspicious file is sent to the sandbox platform.
The source;
E-Mail + Firewall + Web Gateway + Endpoint + ICAP + API + Network Share
can be any of these.
2. Static Analysis
The file is examined structurally before being run.
Hash, header, embedded objects and other technical characteristics can be assessed.
3. Reputation Analysis
File, URL, domain and IP information can be compared with Threat Intelligence sources.
4. Dynamic Analysis
The file is run inside an isolated virtual environment.
5. Behavioral Analysis
The file's;
- Process
- Memory
- File System
- Registry
- Network
- DNS
activity is analyzed.
6. Threat Classification
The file;
Clean / Suspicious / Malicious
can be classified at different risk levels of this kind.
7. Security Response
According to the verdict, one of the;
Allow Block Quarantine CDR SOC Alert
actions can be applied.
Ransomware Sandbox Analysis
Ransomware attacks can generally begin through a malicious file or link sent to the user.
For example, the;
Phishing → Attachment → Malware Execution → Command & Control → Credential Theft → Ransomware
attack chain can form.
By analyzing the malicious file's behavior at the early stages in particular, sandbox technology can help block the attack before it reaches the endpoint.
Phishing Attachment Analysis
In phishing attacks, malicious content is frequently prepared to look like a corporate document.
For example, file names that look normal to the user such as;
Invoice.pdf Quote.docx Order.xlsx Payment_Details.zip
can be used.
By focusing on the file's real behavior rather than its name, the sandbox tries to bring out malicious activity.
What Is Sandbox Evasion?
Advanced malware samples can try to work out that they are running in a sandbox environment.
Using methods such as;
- VM checks
- User activity checks
- Mouse movement checks
- System characteristics
- Sleep timer
- Environment fingerprinting
the attacker may avoid carrying out malicious behavior inside the sandbox.
It is therefore important that advanced sandbox solutions can simulate the real user environment as accurately as possible.
Sandbox and Threat Intelligence
When new malware is detected inside the sandbox, the;
- Hash
- Domain
- URL
- IP
- File Behavior
- C2 Infrastructure
information obtained can be turned into Threat Intelligence data.
This information can be shared with other security systems.
For example;
Sandbox ↓ Malicious Domain Detected ↓ SIEM / SOAR ↓ Firewall Block ↓ EDR IOC Search
an automated security operation of this kind can be built.
Sandbox and SOAR Integration
A sandbox alarm can trigger an automated response process on the SOAR platform.
For example:
Malicious File Detected ↓ Search the Hash in EDR ↓ Block the Domain on the Firewall ↓ Quarantine the E-Mail ↓ Check the User's Endpoint ↓ Create a SOC Incident
a playbook of this kind can be applied.
Sandbox and SIEM Integration
Carrying sandbox security events into the SIEM allows attacks to be assessed in a wider context.
The SIEM can build attack scenarios of higher accuracy by correlating;
Sandbox + Firewall + EDR + Mail + Active Directory + DNS
these events.
On-Premise Sandbox
An on-premise sandbox provides for the analysis infrastructure to run inside the organization's own data center.
It can be important particularly for;
- Public sector
- Defence industry
- Finance
- Critical infrastructure
- Organizations with high data confidentiality
these estates.
In estates where sending files to a cloud service outside the organization is not wanted, an on-premise architecture can be assessed.
Air-Gapped Network Sandbox
Security requirements differ on networks holding no internet connection or isolated from external systems.
Particularly in;
Defence + OT/ICS + SCADA + Critical Infrastructure + R&D
environments, files may be carried over USB or controlled transfer systems.
In these estates, sandbox and CDR technologies play an important role in analyzing the content arriving from removable media securely.
USB File Security and Sandbox
USB devices are one of the significant malware transport channels on closed networks.
When uncontrolled data transfer is carried out in the form of;
Internet Network → USB → Critical Network
air-gap security may in effect have been bypassed.
The secure approach;
USB → Malware Scan → Sandbox → CDR → Approved File → Critical Network
can be designed in this way.
This use case is an important differentiator particularly for DFX Malware Mitigation Sandbox and secure media transfer architectures.
ICAP Sandbox Integration
ICAP is one of the common integration methods allowing different security systems to send files to external analysis services.
The sandbox's ICAP integration allows it to be used together with different systems such as;
- Secure Web Gateway
- Proxy
- File Transfer
- Network Storage
- DLP
- Mail Security
and similar platforms.
How Is a Sandbox POC Carried Out?
A sandbox product should not be chosen on the datasheet alone.
In SecureSys POC work, through controlled scenarios;
File Analysis
Analysis of different file formats.
Zero-Day Simulation
Assessment of non-signature-based behavior.
E-Mail Integration
Testing of the suspicious attachment flow.
CDR
Assessment of documents being rebuilt safely.
SIEM Integration
Transfer of alarm and IOC information into the SIEM.
Performance
Assessment of analysis capacity under heavy file traffic.
False Positive
Examination of the rate at which legitimate corporate files are blocked incorrectly.
Reporting
Checking of the technical detail SOC and Incident Response teams need.
these can be carried out.
What Should You Consider When Choosing a Sandbox Product?
In sandbox selection these criteria should be assessed together:
- Static Analysis
- Dynamic Analysis
- Behavioral Analysis
- Machine Learning / AI
- CDR support
- YARA
- MITRE ATT&CK Mapping
- Threat Intelligence
- E-Mail integration
- Firewall integration
- EDR integration
- ICAP
- API
- SIEM
- SOAR
- Network Share
- USB / Removable Media
- On-Premise
- Cloud
- Air-Gapped operation
- Supported operating systems
- Supported file formats
- Analysis capacity
- Reporting
- IOC generation
- False Positive management
FortiSandbox Solutions in Türkiye
At organizations holding Fortinet infrastructure, FortiSandbox can be assessed particularly for its Security Fabric integration.
FortiGate + FortiMail + FortiClient + FortiWeb + FortiSandbox
this architecture allows the suspicious content arriving from the network, e-mail, endpoint and application security layers to be assessed within a shared threat analysis approach.
At SecureSys, in FortiSandbox projects we address the;
Sizing + Licensing + POC + Deployment + FortiGate Integration + FortiMail Integration + SIEM/SOC Integration
processes end to end.
DFX Malware Mitigation Sandbox Solutions in Türkiye
DFX Malware Mitigation Sandbox can be positioned particularly in projects where;
Sandbox + CDR + Exchange + ICAP + Network Share + USB + Secure File Transfer
these needs are present together.
On critical infrastructure and closed networks, transferring content securely — rather than merely determining whether the file is malicious — is an important security need.
The DFX approach therefore;
Malware Detection + Behavioral Analysis + CDR + Controlled File Transfer
stands out in projects assessing these layers together.
Frequently Asked Questions About Sandbox Solutions
What is a sandbox security solution?
A sandbox is the cyber security technology providing for suspicious files and content to be run in secure environments isolated from real systems so their behavior is analyzed.
Does a sandbox replace antivirus?
No. Antivirus and sandbox complete one another. While antivirus provides fast protection against known threats, a sandbox focuses particularly on the behavioral analysis of unknown and advanced threats.
Does a sandbox detect zero-day attacks?
One of a sandbox's core use cases is analyzing the behavior of suspicious files for which no known signature yet exists. No security technology, however, guarantees the complete detection of every zero-day attack on its own.
What is CDR?
Content Disarm & Reconstruction is the file security technology aiming to build a safe copy by removing the potentially dangerous active components inside a document.
Can a sandbox be deployed on-premise?
While this varies by product, on-premise sandbox architectures do exist. This model can be preferred at organizations holding data confidentiality, regulatory or closed network requirements.
Which systems is a sandbox integrated with?
Depending on the architecture it can be integrated with firewalls, secure email gateways, EDR, proxies, SIEM, SOAR, ICAP-capable systems, file sharing platforms and different security technologies.
How is sandbox pricing determined?
Sandbox pricing can vary according to the product, deployment model, analysis capacity, number of users or devices, appliance capacity, licence period and security services.
For correct pricing, therefore, the organization's file traffic and integration requirements need determining first.
SecureSys Sandbox Solutions
At SecureSys we offer the;
Consultancy → Product Selection → Sizing → Demo → POC → Licensing → Deployment → Integration → SIEM/SOC Integration → Technical Support
processes for the FortiSandbox and DFX Malware Mitigation Sandbox solutions end to end.
Stop the Unknown Threat Before It Reaches the User
In advanced malware attacks, relying on known IOCs and signatures alone is not enough.
It is necessary to analyze what the file does before what it is.
With the FortiSandbox and DFX Malware Mitigation Sandbox solutions, analyze zero-day, ransomware, malicious document and advanced malware threats in isolated environments; protect your e-mail, web, file transfer and critical networks against advanced threats.
Request a demo, POC and quote for Sandbox Solutions, FortiSandbox and DFX
Do Not Trust an Unknown File — See Its Behavior First
Signature-based security can recognize the known threat. A sandbox technology's real value, in turn, is that it can analyze content not yet known in a secure environment.
With the SecureSys FortiSandbox and DFX Malware Mitigation Sandbox solutions, analyze the unknown threats in your e-mail, web, file and critical data transfer channels before they reach the user or the critical system.
Request a demo, POC and quote for Sandbox Solutions
Want to learn more about this service?
Our expert team will reach out for a free consultation as soon as possible.