Sandboxing (Attachment Sandboxing)

Sandboxing is the controlled execution and analysis of suspicious files or programs in an isolated environment. In the email environment (attachment sandboxing), attachments are checked before they are delivered to recipients or opened.

The aim is to observe the behavior of a file in a controlled manner and to detect malicious actions at an early stage: in the sandbox, the file is “detonated” while system access, network connections and process behavior are logged. This is effective because modern malware deliberately bypasses classic signature and rule checks – behavior-based analysis also detects previously unknown malicious functions. Advanced malware, however, tries to detect sandbox environments and behave inconspicuously; good solutions disguise their analysis environment accordingly.

For organizations, sandboxing is an important protective building block against manipulated documents, hidden malicious functions in office or archive files and attacks that exploit a Zero-Day Exploit – i.e. gaps for which no signatures yet exist.