What is a Sandbox?
Simply put, a suspicious attachment is not executed on the user's actual system but is tested in various external system environments to observe how the file behaves. This protects the underlying system from potential changes.
What is the ATP Sandbox Engine?
The Sandbox Engine is a feature of Advanced Threat Protection that scans emails for possible malware by running the files in a virtual and isolated test environment from Hornetsecurity, identifying potentially dangerous effects.
In doing so, the Sandbox Engine uses a system network of secured virtual machines that open suspicious emails, execute included attachments, and check for malicious code. Static, behavior-based, and network-oriented analyses are performed.
This way, unknown and known threats can be examined in a safe and preliminary environment without any risk to the target network and the email recipient.
How does the ATP Sandbox Engine work?
The Sandbox Engine employs the following analysis methods:
| The static analysis involves a comparison with known signatures (matching with more than 20 antivirus engines), metadata, and keywords of known malware. |
| The behavior-based analysis can detect attempts to identify virtualization layers, changes in the registry, (system) API calls, hidden threads, commands, and services. |
| In the network-based analysis, connections to DNS servers, command and control servers, and websites for downloading malicious code are recorded. |
If it turns out that the received attachment is malware, the emails are directly moved to quarantine and marked with the category AdvThreat. This means that at least one attachment of the email was dynamically analyzed by the Sandbox Engine and classified as malicious.
The results are recorded in an ATP report, which can then be used for IT forensic analysis:

What is the ATP scan?
For customers using the Advanced Threat Protection service, emails are already automatically analyzed by the Sandbox Engine.
The manual ATP scan therefore primarily serves as an additional security measure for ATP customers, for example before manually delivering an email categorized as AdvThreat, and additionally provides an ATP report.
The ATP scan can only be applied to emails with executable attachments, for example, emails with .exe files. Already delivered valid emails can only be scanned with the ATP scan if Archiving or Continuity Service is activated.
The scan is started in the Control Panel under Email Security > Email Live Tracking. For more information, please refer to the following article from our manual: Starting the ATP scan
Once the scan is complete, the ATP report can be accessed in the advanced function view of the email under ATP Scan.
Note: Even customers without a subscribed ATP can perform ATP scans; however, the number is limited. Additional ATP scans are only possible if ATP has been purchased as a paid service.