Sandboxes¶
The sandbox produces the dynamic evidence: the process tree, network activity,
the sandbox's own signatures, dropped files, registry and the rest. The
dynamic analyst reads that report through in-process tools, with no transport
to open, and the network analyst reads its capture. core.sandbox.provider
picks the provider; a job can pick its own with sandbox_provider.
| Provider | Detonates | Reached at |
|---|---|---|
mock (default) |
nothing | — |
cape2 |
on your CAPEv2 instance | sandbox.cape2.base_url |
triage |
on Hatching Triage's cloud | sandbox.triage.base_url, https://tria.ge/api/v0 by default |
upload |
nothing of its own: reads a report produced elsewhere | — |
rest |
on any HTTP sandbox you describe | sandbox.rest.base_url |
A sandbox runs the sample
Point Maljan only at a sandbox you are authorised to use, on a network isolated from production. What a submission discloses depends on the service: a cloud sandbox holds the sample under its own terms.
Mock¶
The default executes nothing. It returns a recorded fixture for a sample it has
one for, marked recorded_fixture, and an empty stand-in marked synthetic for
any other. Where no sandbox ran, the triage pack writes one sandbox_status
entry with the sentence that says so, the dynamic and network analysts are
skipped, the run carries the reason, and a stand-in's empty sections are never
rendered as "0 processes". See Providers.
CAPEv2¶
| Setting | Default | Notes |
|---|---|---|
sandbox.cape2.base_url |
http://localhost:8000 |
The CAPE REST API. |
sandbox.cape2.api_token |
empty | Stored encrypted. |
sandbox.cape2.timeout_seconds |
300 |
How long to wait for the report. |
sandbox.cape2.poll_interval_seconds |
10 |
|
sandbox.cape2.package_by_format |
{} |
A file type to a CAPE analysis package, e.g. {"apk": "apk", "elf": "generic", "pdf": "pdf", "ooxml": "doc"}; * is the fallback, and a format with no entry is submitted without a package so CAPE picks one. |
sandbox.cape2.submit_options |
{} |
Sent verbatim as further form fields (machine, tags, options, timeout, anything tasks/create/file accepts). |
sandbox.cape2.mcp |
disabled | An optional CAPE MCP server beside the REST API. |
The guest platform is sent when CAPE has a name for it (windows, linux,
android) and left unset otherwise. An APK detonated with the exe package
produces nothing, which is what package_by_format is for.
Hatching Triage¶
| Setting | Default | Notes |
|---|---|---|
sandbox.triage.base_url |
https://tria.ge/api/v0 |
|
sandbox.triage.api_token |
empty | Stored encrypted. |
sandbox.triage.profile |
empty | The VM profile; empty means the account default. |
sandbox.triage.profile_by_format |
{} |
A file type to a VM profile, with * as its fallback and profile behind that, so an APK reaches an Android profile. |
sandbox.triage.analysis_seconds |
unset | How long the VM runs the sample, sent as defaults.timeout; unset leaves Triage's own default. |
sandbox.triage.timeout_seconds |
900 |
How long the platform waits for the report. Must be longer than analysis_seconds, and validation refuses one that is not. |
sandbox.triage.poll_interval_seconds |
15 |
|
sandbox.triage.fetch_pcap |
true |
Fetches the capture for the network analyst. |
A value the account does not allow is refused by Triage, and the submission error quotes Triage's own words and names the setting. The run summary states the run-time limit Triage set for the task: a limit, not a measured duration.
An uploaded report¶
The upload provider reads a report produced elsewhere instead of detonating:
attach it to the sample with POST /api/v1/samples/{sample_id}/sandbox-reports,
then name it on the job with sandbox_report_id, which also selects this
provider. CAPEv2, Cuckoo and Triage formats are accepted by default
(sandbox.upload.allowed_formats), up to 64 MiB (sandbox.upload.max_report_bytes).
Only a report attached to the job's own sample is read. See Running an
analysis.
Any REST sandbox¶
The rest provider describes a sandbox Maljan has never heard of, rather than
coding it:
| Block | What it says |
|---|---|
sandbox.rest.auth |
The header, scheme and token the API takes. |
sandbox.rest.submit |
The multipart submission (method, path, file_field, extra_fields, submit_fields) and the JSONPath of the task id in its answer. |
sandbox.rest.status |
The poll path, the JSONPath of the state, and the done and failed values. |
sandbox.rest.report |
Where the report is, its format (cape2, cuckoo, triage or generic) and an optional capture path. |
sandbox.rest.mapping |
For a generic report, an RFC 9535 JSONPath per channel: processes, calls, signatures, DNS, HTTP, TCP, UDP, hosts, domains, dropped files, registry. |
An empty path in mapping says the sandbox does not publish that channel, and
the report lists it as unavailable rather than reading like a clean sample by
omission. mapping.channels maps a channel name of your own to a JSONPath for
anything the schema has no field for; namespace it by platform, e.g.
{"android.permissions": "$.apk.permissions[*]"}. See Format routing and the
sandbox.
Connection tests¶
The Connect a sandbox setup guide walks provider choice, credentials and a
connection test. The cape2, triage and rest probes back its Test buttons.