Integrate file reputation services and sandboxes

Integrating Engines with file reputation services and sandboxes improves the malware detection coverage of SMCaaS when you use file filtering.

Engine Editor > Add-Ons > File Reputation

Use this branch to enable file reputation services for file filtering.

Option Definition
File Reputation Service Select the file reputation service to use.
  • None — Disables file reputation services.
  • Global Threat Intelligence (GTI) — Enables the use of McAfee GTI file reputation services for file filtering. This service must be enabled also in the Global System Properties.
Option Definition
When File Reputation Service is Global Threat Intelligence (GTI)
HTTP Proxies

(Optional)

When specified, requests are sent through an HTTP proxy instead of the Engine accessing the external network directly. Click Add to add an element to the list, or Remove to remove the selected element.
Note: You can only use one HTTP proxy for the connection to the McAfee Global Threat Intelligence file reputation service. If you select more than one HTTP proxy, the additional HTTP proxies are ignored.

Engine Editor > Add-Ons > Sandbox

Use this branch to select and configure sandbox servers for Engines.

Option Definition
Sandbox Type Specifies which type of sandbox the Engine uses for sandbox file reputation scans.
  • None — The Engine does not use a sandbox.
  • Cloud Sandbox - Advanced Malware Detection & Protection — The Engine uses the Advanced Malware Detection & Protection cloud service for sandbox analysis and file reputation scan.
    Note: This is a licensed service which requires a subscription to use.
  • Local Sandbox - Advanced Malware Detection & Protection — The Engine uses the Advanced Malware Detection & Protection cloud service for sandbox analysis and file reputation scan.
    Note: This is a licensed service which requires a local AMDP server to use.
Option Definition
When Sandbox Type is Cloud Sandbox - Advanced Malware Detection & Protection
Sandbox Service Specifies the sandbox service that the Engine contacts to request a file reputation with the file hash (SHA256), and if not found, sends the file for sandbox analysis. Click Select to select an element.
HTTP Proxies

(Optional)

When specified, requests are sent through an HTTP proxy instead of the Engine accessing the external network directly.

Add — Allows you to add an HTTP Proxy to the list.

Remove — Removes the selected HTTP Proxy from the list.

Option Definition
When Sandbox Type is Local Sandbox - Advanced Malware Detection & Protection
Sandbox Service Specifies the sandbox service that the Engine contacts to request file reputation scans. Click Select to select an element.
HTTP Proxies

(Optional)

When specified, requests are sent through an HTTP proxy instead of the Engine accessing the external network directly.

Add — Allows you to add an HTTP Proxy to the list.

Remove — Removes the selected HTTP Proxy from the list.