This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Sandstorm issue

Currently running UTM 9.4 and testing out Sandstorm functions.

Bit odd at the moment as everything seemed to be working but the last 2 days it seems to have stopped. The advanced protection screen shows 8 Suspicious files but none have been send for analasys.

I had an email from the admin lady this morning asking if an email she had received was legitimate. I sent a sample of the document she received to the labs manually and it has come back as malicious and a pattern file is being created. Why did the UTM not send this to sandbox even though it was marked as suspicious?

No config has been changed. A little worrying that stuff like this getting through!



This thread was automatically locked due to age.
Parents
  • Hi Tharil,

    Greetings.

    Please check if you have selected the "Send suspicious content to SophosLabs for analysis" option. You can find this option by navigating to Management> system settings> Scan settings> Send suspicious content to SophosLabs for analysis.

    Let me know if you have any further questions.

    Thanks

    Sachin Gurung

    Sachin Gurung
    Team Lead | Sophos Technical Support
    Knowledge Base  |  @SophosSupport  |  Video tutorials
    Remember to like a post.  If a post (on a question thread) solves your question use the 'This helped me' link.

  • Hi Sachin,

    Yes Sandstorm is enabled. It does send some stuff for sandboxing but too many are being ignored that contain malicious code. A little concerning.

Reply Children
No Data