# Mail & Sandbox Security Solutions

**URL:** https://securesys.com.tr/en/services/mail-sandbox-security-solutions

### Analyze Unknown Files Before They Reach the User

E-mail, web, file sharing systems and removable media are the core channels attackers use to deliver malicious content to organizations.

Traditional antivirus technologies provide an important security layer in detecting known threats. But **zero-day malware, ransomware, phishing attachments, malicious Office documents, script-based attacks and sandbox evasion techniques** have made more advanced analysis mechanisms necessary.

The core approach of sandbox technology is this:

**Suspicious File → Isolated Environment → Static/Dynamic Analysis → Behavior Analysis → Verdict → Block / Quarantine / Allow**

A suspicious file can thereby be examined in a secure and isolated environment before being run on the user's system.

#### What Is a Sandbox?

A sandbox is the advanced threat detection technology allowing unknown or suspicious files to be run in virtual environments isolated from the organization's real systems so their behavior is analyzed.

During analysis the file's behavior such as;

- Creating new processes
- Changing the registry
- Creating or deleting files
- Establishing network connections
- Carrying out DNS queries
- Reaching a Command & Control server
- Running PowerShell or scripts
- Attempting to establish persistence

can be tracked.

#### Static and Dynamic Analysis

In modern sandbox platforms two approaches can be used together.

**Static analysis** analyzes the file's structural characteristics without running it.

**Dynamic analysis**, in turn, observes its behavior by actually running the file in a controlled virtual environment.

Dynamic analysis offers a significant advantage particularly with unknown malware and zero-day threats.

#### Sandbox + E-Mail Security

Rather than an e-mail attachment being delivered to the user directly, it can be put through security layers:

**Internet → Mail Security Gateway → Antivirus → Sandbox → Behavioral Analysis → Safe / Malicious → User**

Should suspicious content be assessed as malicious, it can be blocked or quarantined before reaching the user.

#### CDR – Content Disarm & Reconstruction

One of the important technologies that can be assessed alongside a sandbox is **Content Disarm & Reconstruction**.

CDR's approach goes beyond trying to find the malicious content.

The file's active and potentially dangerous components are stripped out so a safe version can be rebuilt.

This approach can form an important additional security layer particularly in attacks carried out through;

**PDF + Word + Excel + PowerPoint + other corporate documents**

these formats.

#### Zero-Day Malware

Zero-day malware may not yet hold a known signature or IOC.

In this situation classic antivirus can miss the threat with the;

**Hash unknown → No signature found**

result.

A sandbox, by contrast, can look less at who the file is than at **what it does**.

Sandbox technologies therefore play an important role in detecting unknown threats.

#### Sandbox and MITRE ATT&CK

Advanced sandbox solutions can relate the malware behavior they observe to MITRE ATT&CK techniques.

For example;

**Execution → Persistence → Defense Evasion → Credential Access → Command & Control**

behavior of this kind can give the analyst clearer context about the nature of the attack.

**Sandbox + [SIEM](/en/services/siem-and-soar-security-service) \+ SOC**

Carrying sandbox results into the SIEM allows the attack chain to be related to other security systems.

For example:

**Mail Gateway → Suspicious attachment + Sandbox → Malicious verdict + EDR → Endpoint execution + Firewall → C2 connection**

can be assessed by the SOC within a single attack chain.

### Fortinet FortiSandbox

#### AI Supported Advanced Malware and Zero-Day Analysis

Fortinet FortiSandbox is Fortinet's advanced sandbox platform for detecting unknown and advanced threats.

FortiSandbox aims to detect zero-day threats, ransomware, malware and advanced attacks by using static and dynamic analysis, advanced AI/ML and FortiGuard Labs threat intelligence together.

#### Advanced AI and Machine Learning

In FortiSandbox's current architecture, purpose-built machine learning and AI models are used to speed up threat analysis and identify unknown attacks.

Assessing static and dynamic analysis results together with threat intelligence provides broader security context.

#### Fortinet Security Fabric Integration

One of FortiSandbox's important advantages is its integration with the Fortinet ecosystem.

**FortiGate + FortiMail + FortiClient + FortiWeb + FortiSandbox + FortiAnalyzer / FortiSIEM**

can be run together.

In Fortinet's current technical documentation, alongside the FortiGate, FortiMail, FortiClient EMS and FortiWeb integrations, different integration methods such as file submission over ICAP, network share and API are also supported.

#### E-Mail Security

Used together with FortiMail, suspicious e-mail attachments can be sent to FortiSandbox and analyzed before reaching the user.

#### Endpoint Security

Together with the FortiClient/Fortinet endpoint ecosystem, suspicious files can be sent for sandbox analysis and malicious content brought into endpoint security processes.

#### OT and Air-Gapped Environments

FortiSandbox is not aimed at standard IT environments alone. Current Fortinet documentation also holds deployment support for OT protocols and **air-gapped network** support. This capability is important in critical infrastructure and isolated network projects.

#### Deployment Options

FortiSandbox;

**Hardware + Virtual Appliance + SaaS + PaaS**

can be positioned with these options. Different models can thereby be applied according to the organization's data sovereignty, performance and architecture requirements.

#### Who Is FortiSandbox Suitable For?

It forms a strong alternative particularly at **organizations using the Fortinet Security Fabric, wanting advanced malware analysis, holding high-volume file traffic, running a SOC operation or needing zero-day protection in IT/OT environments**.

### DFX Malware Mitigation Sandbox

#### AI Supported Sandbox, CDR and Multi-Vector Analysis

DFX Malware Mitigation Sandbox is an advanced sandbox platform running suspicious files in isolated virtual environments to analyze malicious behavior and aiming to neutralize threats.

DFX's notable side is that it does not limit sandbox analysis to e-mail attachments alone.

The platform can carry out central analysis by accepting files from different attack vectors such as;

**E-Mail Attachments + Network Files + Hardware / USB + Web Documents**

simultaneously.

#### Isolated Virtual Execution

Suspicious files are run in virtual environments separated from the organization's real systems.

Through purpose-built VM profiles, DFX aims to trigger evasive malware by imitating real user behavior and to analyze its behavior.

#### Advanced AI Scan

In DFX's advanced analysis layer;

**AI Behavioral Categorization + YARA + MITRE ATT&CK**

are used together.

The aim is thereby to assess suspicious behavior without relying on known malware signatures alone.

#### Content Disarm & Reconstruction

One of DFX's important differentiators is that it brings the **CDR – Content Disarm & Reconstruction** capability into the sandbox approach.

The active or risky components inside a suspicious document are cleaned so safe content can be delivered to the user.

This approach:

**Detect → Analyze → Disarm → Reconstruct → Deliver**

can go beyond the classic "block it if it is malicious" model in this way.

#### Microsoft Exchange Integration

DFX Malware Mitigation Sandbox can work integrated with Microsoft Exchange.

Attachments such as PDF or Office documents in incoming e-mail can be analyzed in a secure virtual environment and assessed before delivery to the user.

#### ICAP Integration

Thanks to ICAP support, the sandbox can be integrated with different security gateway and file transfer architectures.

This capability makes it easier to position DFX not merely as an e-mail sandbox but as a corporate **file security** component.

#### Network Share Security

Files moving over a network share being brought into automated analysis provides an additional security layer particularly at organizations holding shared file areas.

#### USB and Critical Infrastructure Security

Removable media security also stands out separately in the DFX ecosystem. DFX Media Transfer Station aims to make data transfer into sensitive networks secure by putting removable media such as USB through anti-malware, sandbox and CDR processes.

This approach can be an important differentiator particularly for;

**Defence Industry + OT/ICS + SCADA + Closed Networks + Critical Infrastructure**

these estates.

#### Detailed Reports & Audit

As a result of its analysis, DFX offers detailed reporting on file and process activity along with network behavior. Its Threat Intelligence layer is also used to relate IOC and hash data to real threat context.

#### Who Is DFX Suitable For?

It can be positioned as a strong alternative particularly for;

**Critical infrastructure, the defence industry, closed networks, OT environments, organizations carrying out sensitive file transfer and organizations wanting to use sandbox and CDR technology together**

these estates.

### FortiSandbox or DFX Malware Mitigation Sandbox?

It is more accurate not to describe the two products here as direct copies of one another.

#### FortiSandbox

**Fortinet Security Fabric + FortiGate + FortiMail + FortiClient + FortiWeb + AI/ML Sandbox + IT/OT + SOC**

stands out in projects where this ecosystem matters.

#### DFX Malware Mitigation Sandbox

**Sandbox + CDR + ICAP + Exchange + Network Share + USB/File Security + Critical Infrastructure**

differentiates itself in projects where this approach matters.

#### The SecureSys Mail & Sandbox Approach

At SecureSys, in sandbox projects we can address not merely product deployment but the;

**Attack Vector Analysis → Determining Mail/File Flows → Product Selection → POC → Sandbox Integration → Mail Gateway Integration → ICAP / File Transfer Integration → CDR Policies → SIEM/SOC Integration → Incident Response**

processes together.

### Advanced Malware and Zero-Day Protection with Sandbox Solutions

Traditional antivirus, firewall and e-mail security systems continue to be core components of corporate cyber security. Today, however, attackers use continuously changing malware samples, obfuscation techniques, encrypted payloads, malicious documents and previously unseen attack methods so they can evade security systems.

It is therefore important that organizations make **advanced malware analysis and sandbox security** technologies part of their security architecture.

Sandbox solutions analyze the behavior of suspicious files and content by running them in controlled environments isolated from real user systems.

The aim is thereby to detect different threats such as;

**Known Malware + Unknown Malware + Zero-Day + Ransomware + Malicious Document + Phishing Attachment + Script + Exploit**

and similar attacks.

With the **Fortinet FortiSandbox and DFX Malware Mitigation Sandbox** technologies, SecureSys raises organizations' security level against the advanced threats in their e-mail, web, network, file transfer and critical infrastructure.

### What Is a Malware Sandbox?

A malware sandbox is the cyber security technology providing for suspicious files to be run in a secure and isolated analysis environment so their malicious behavior is detected.

A file's hash not being present in known malware databases does not mean the file is safe.

Particularly with newly created malware samples, no antivirus signature may exist yet.

At this point a sandbox analyzes not merely the file's identity but its **behavior**.

If the file carries out the;

**Word → PowerShell → Encoded Command → Payload Download → Registry Persistence → Command & Control**

behavior after running, for example, the sandbox can assess the file as a potential attack.

### What Is an E-Mail Sandbox?

E-mail sandbox technology provides for the suspicious files in incoming or outgoing e-mail to be analyzed in an isolated environment before reaching the user.

Particularly;

- PDF
- Microsoft Word
- Excel
- PowerPoint
- ZIP
- Executable
- Script
- Archive

files can be used by attackers to carry malicious content.

A typical **E-Mail Sandbox** architecture:

**Internet → Secure Email Gateway → Antivirus / Reputation → Sandbox → Behavioral Analysis → Verdict → Mailbox**

can be built in this way.

Should the file be assessed as malicious, the e-mail can be quarantined or blocked according to the organization's security policy.

### What Is Zero-Day Sandbox Protection?

Zero-day attacks can exploit threats not yet known to the vendor or for which no security signature has been built.

A signature-based security approach alone may therefore not be enough against zero-day attacks.

Sandbox technology helps detect unknown threats by bringing;

#### Behavior Instead of Signature

this analysis into play.

This capability makes sandbox systems one of the important components of **Advanced Threat Protection – ATP** architecture.

### Advanced Threat Protection – ATP

Advanced Threat Protection means more than one security technology being used together to detect advanced and targeted attacks.

A typical ATP architecture;

**Antivirus + Reputation + Threat Intelligence + Static Analysis + Dynamic Analysis + Machine Learning + Sandbox + CDR**

can consist of these components.

The aim is to put threats through different analysis layers rather than depending on a single security engine.

### What Is the Difference Between a Sandbox and Antivirus?

Antivirus and sandbox are not alternatives to one another.

Antivirus is used particularly for detecting known threats quickly.

A sandbox, in turn, focuses on the unknown and suspicious files requiring deeper analysis.

**Antivirus:** "Have we seen this file as malicious before?"

**Sandbox:** "What does this file do when it runs?"

In an advanced security architecture the two technologies can therefore be used together.

### What Is the Difference Between a Sandbox and EDR?

EDR and sandbox work at different security layers.

A **sandbox** focuses on analyzing suspicious content before it reaches or runs on the user's system.

**EDR** monitors the activity taking place on the real endpoint continuously.

For example, the;

**Mail → Sandbox → Endpoint → EDR**

architecture can be applied.

While the sandbox tries to stop the attack before it reaches the user, EDR detects the attack activity taking place on the endpoint.

### What Is the Difference Between a Sandbox and CDR?

Sandbox and CDR are two different security approaches completing one another.

**Sandbox:** Analyzes whether the file is malicious.

**CDR – Content Disarm & Reconstruction:** Tries to build a safe file by cleaning the potentially risky active content inside the file.

For example:

**Original Word Document ↓ CDR ↓ Macro / Active Content Removal ↓ Reconstructed Document ↓ User**

this approach can be applied.

Particularly in document security, therefore;

#### Sandbox + CDR

together can form a strong security layer.

### Which Files Can a Sandbox Analyze?

Depending on the product and licence model, different file types can be analyzed.

Among these can be different content such as;

- PDF
- DOC / DOCX
- XLS / XLSX
- PPT / PPTX
- EXE
- DLL
- ZIP
- RAR
- JavaScript
- PowerShell
- Script
- URL
- HTML

and similar formats.

Because supported file formats can vary by product and version, the vendor's current technical matrix should be checked before the project.

### How Does a Sandbox Work?

A typical sandbox analysis process consists of the following stages.

#### \1. File Submission

The suspicious file is sent to the sandbox platform.

The source;

**E-Mail + Firewall + Web Gateway + Endpoint + ICAP + API + Network Share**

can be any of these.

#### \2. Static Analysis

The file is examined structurally before being run.

Hash, header, embedded objects and other technical characteristics can be assessed.

#### \3. Reputation Analysis

File, URL, domain and IP information can be compared with Threat Intelligence sources.

#### \4. Dynamic Analysis

The file is run inside an isolated virtual environment.

#### \5. Behavioral Analysis

The file's;

- Process
- Memory
- File System
- Registry
- Network
- DNS

activity is analyzed.

#### \6. Threat Classification

The file;

**Clean / Suspicious / Malicious**

can be classified at different risk levels of this kind.

#### \7. Security Response

According to the verdict, one of the;

**Allow Block Quarantine CDR SOC Alert**

actions can be applied.

### Ransomware Sandbox Analysis

Ransomware attacks can generally begin through a malicious file or link sent to the user.

For example, the;

**Phishing → Attachment → Malware Execution → Command & Control → Credential Theft → Ransomware**

attack chain can form.

By analyzing the malicious file's behavior at the early stages in particular, sandbox technology can help block the attack before it reaches the endpoint.

### Phishing Attachment Analysis

In phishing attacks, malicious content is frequently prepared to look like a corporate document.

For example, file names that look normal to the user such as;

**Invoice.pdf Quote.docx Order.xlsx Payment_Details.zip**

can be used.

By focusing on the file's real behavior rather than its name, the sandbox tries to bring out malicious activity.

### What Is Sandbox Evasion?

Advanced malware samples can try to work out that they are running in a sandbox environment.

Using methods such as;

- VM checks
- User activity checks
- Mouse movement checks
- System characteristics
- Sleep timer
- Environment fingerprinting

the attacker may avoid carrying out malicious behavior inside the sandbox.

It is therefore important that advanced sandbox solutions can simulate the real user environment as accurately as possible.

### Sandbox and Threat Intelligence

When new malware is detected inside the sandbox, the;

- Hash
- Domain
- URL
- IP
- File Behavior
- C2 Infrastructure

information obtained can be turned into **Threat Intelligence** data.

This information can be shared with other security systems.

For example;

**Sandbox ↓ Malicious Domain Detected ↓ SIEM / SOAR ↓ Firewall Block ↓ EDR IOC Search**

an automated security operation of this kind can be built.

### Sandbox and SOAR Integration

A sandbox alarm can trigger an automated response process on the SOAR platform.

For example:

**Malicious File Detected ↓ Search the Hash in EDR ↓ Block the Domain on the Firewall ↓ Quarantine the E-Mail ↓ Check the User's Endpoint ↓ Create a SOC Incident**

a playbook of this kind can be applied.

### Sandbox and SIEM Integration

Carrying sandbox security events into the SIEM allows attacks to be assessed in a wider context.

The SIEM can build attack scenarios of higher accuracy by correlating;

**Sandbox + Firewall + EDR + Mail + Active Directory + DNS**

these events.

### On-Premise Sandbox

An on-premise sandbox provides for the analysis infrastructure to run inside the organization's own data center.

It can be important particularly for;

- Public sector
- Defence industry
- Finance
- Critical infrastructure
- Organizations with high data confidentiality

these estates.

In estates where sending files to a cloud service outside the organization is not wanted, an on-premise architecture can be assessed.

### Air-Gapped Network Sandbox

Security requirements differ on networks holding no internet connection or isolated from external systems.

Particularly in;

**Defence + OT/ICS + SCADA + Critical Infrastructure + R&D**

environments, files may be carried over USB or controlled transfer systems.

In these estates, sandbox and CDR technologies play an important role in analyzing the content arriving from removable media securely.

### USB File Security and Sandbox

USB devices are one of the significant malware transport channels on closed networks.

When uncontrolled data transfer is carried out in the form of;

**Internet Network → USB → Critical Network**

air-gap security may in effect have been bypassed.

The secure approach;

**USB → Malware Scan → Sandbox → CDR → Approved File → Critical Network**

can be designed in this way.

This use case is an important differentiator particularly for **DFX Malware Mitigation Sandbox and secure media transfer architectures**.

### ICAP Sandbox Integration

ICAP is one of the common integration methods allowing different security systems to send files to external analysis services.

The sandbox's ICAP integration allows it to be used together with different systems such as;

- Secure Web Gateway
- Proxy
- File Transfer
- Network Storage
- DLP
- Mail Security

and similar platforms.

### How Is a Sandbox POC Carried Out?

A sandbox product should not be chosen on the datasheet alone.

In SecureSys POC work, through controlled scenarios;

#### File Analysis

Analysis of different file formats.

#### Zero-Day Simulation

Assessment of non-signature-based behavior.

#### E-Mail Integration

Testing of the suspicious attachment flow.

#### CDR

Assessment of documents being rebuilt safely.

#### SIEM Integration

Transfer of alarm and IOC information into the SIEM.

#### Performance

Assessment of analysis capacity under heavy file traffic.

#### False Positive

Examination of the rate at which legitimate corporate files are blocked incorrectly.

#### Reporting

Checking of the technical detail SOC and Incident Response teams need.

these can be carried out.

### What Should You Consider When Choosing a Sandbox Product?

In sandbox selection these criteria should be assessed together:

- Static Analysis
- Dynamic Analysis
- Behavioral Analysis
- Machine Learning / AI
- CDR support
- YARA
- MITRE ATT&CK Mapping
- Threat Intelligence
- E-Mail integration
- Firewall integration
- EDR integration
- ICAP
- API
- SIEM
- SOAR
- Network Share
- USB / Removable Media
- On-Premise
- Cloud
- Air-Gapped operation
- Supported operating systems
- Supported file formats
- Analysis capacity
- Reporting
- IOC generation
- False Positive management

### FortiSandbox Solutions in Türkiye

At organizations holding Fortinet infrastructure, FortiSandbox can be assessed particularly for its Security Fabric integration.

**FortiGate + FortiMail + FortiClient + FortiWeb + FortiSandbox**

this architecture allows the suspicious content arriving from the network, e-mail, endpoint and application security layers to be assessed within a shared threat analysis approach.

At SecureSys, in FortiSandbox projects we address the;

**Sizing + Licensing + POC + Deployment + FortiGate Integration + FortiMail Integration + SIEM/SOC Integration**

processes end to end.

### DFX Malware Mitigation Sandbox Solutions in Türkiye

DFX Malware Mitigation Sandbox can be positioned particularly in projects where;

**Sandbox + CDR + Exchange + ICAP + Network Share + USB + Secure File Transfer**

these needs are present together.

On critical infrastructure and closed networks, transferring content securely — rather than merely determining whether the file is malicious — is an important security need.

The DFX approach therefore;

**Malware Detection + Behavioral Analysis + CDR + Controlled File Transfer**

stands out in projects assessing these layers together.

### Frequently Asked Questions About Sandbox Solutions

#### What is a sandbox security solution?

A sandbox is the cyber security technology providing for suspicious files and content to be run in secure environments isolated from real systems so their behavior is analyzed.

#### Does a sandbox replace antivirus?

No. Antivirus and sandbox complete one another. While antivirus provides fast protection against known threats, a sandbox focuses particularly on the behavioral analysis of unknown and advanced threats.

#### Does a sandbox detect zero-day attacks?

One of a sandbox's core use cases is analyzing the behavior of suspicious files for which no known signature yet exists. No security technology, however, guarantees the complete detection of every zero-day attack on its own.

#### What is CDR?

Content Disarm & Reconstruction is the file security technology aiming to build a safe copy by removing the potentially dangerous active components inside a document.

#### Can a sandbox be deployed on-premise?

While this varies by product, on-premise sandbox architectures do exist. This model can be preferred at organizations holding data confidentiality, regulatory or closed network requirements.

#### Which systems is a sandbox integrated with?

Depending on the architecture it can be integrated with firewalls, secure email gateways, EDR, proxies, SIEM, SOAR, ICAP-capable systems, file sharing platforms and different security technologies.

#### How is sandbox pricing determined?

Sandbox pricing can vary according to the product, deployment model, analysis capacity, number of users or devices, appliance capacity, licence period and security services.

For correct pricing, therefore, the organization's file traffic and integration requirements need determining first.

### SecureSys Sandbox Solutions

At SecureSys we offer the;

**Consultancy → Product Selection → Sizing → Demo → POC → Licensing → Deployment → Integration → SIEM/SOC Integration → Technical Support**

processes for the **FortiSandbox and DFX Malware Mitigation Sandbox** solutions end to end.

### Stop the Unknown Threat Before It Reaches the User

In advanced malware attacks, relying on known IOCs and signatures alone is not enough.

It is necessary to analyze **what the file does before what it is**.

**With the FortiSandbox and DFX Malware Mitigation Sandbox solutions, analyze zero-day, ransomware, malicious document and advanced malware threats in isolated environments; protect your e-mail, web, file transfer and critical networks against advanced threats.**

**Request a demo, POC and quote for Sandbox Solutions, FortiSandbox and DFX**

### Do Not Trust an Unknown File — See Its Behavior First

Signature-based security can recognize the known threat. A sandbox technology's real value, in turn, is that it **can analyze content not yet known in a secure environment**.

**With the SecureSys FortiSandbox and DFX Malware Mitigation Sandbox solutions, analyze the unknown threats in your e-mail, web, file and critical data transfer channels before they reach the user or the critical system.**

**Request a demo, POC and quote for Sandbox Solutions**
