The Quicksand is a file sandbox. It performs automated malware analysis and runs deep heuristic analysis against Microsoft Office Documents and PDF files. This sandbox runs on the gateway, which means that your files are not uploaded to third party services. All the files analyzed by the Quicksand will never leave your ESG for privacy reasons. From this page you can customize the Quicksand behavior.
Configuration
From the first tab of this page you can configure the Quicksand engine, customizing its settings.
General
From this section you can enable, disable or run this engine in Dry-run mode for testing purposes. The Dry-run mode is a testing mode used to make sure that the sandbox works correctly. The sandbox actions are only logged on message analysis. but not performed on the document.
PDF Documents
From this section to enable or disable the external links disarming in PDF documents. When this option is enabled you can set to add an attachment warning to the email or don't.
Documents with active content
Documents sent via email may contain active content, which can be executed on the client. For examples PDF documents may contain Javascript code. For each content category you can configure the action will be performed.
- Action to perform on Safe active contents
- Action to perform on Suspect active contents
- Action to perform on Indeterminate active contents
- Action to perform on Encrypted Docs with Active Content
Note: documents without active content aren't affected by Quicksand and always delivered.
Exceptions
You can create policies for which the Quicksand sanitizations will not be executed. For consistency reasons this policies are configurable in the Attachment Filters page.