Fortinet black logo

sandboxing-prefilter

sandboxing-prefilter

Allow user to turn FortiGuard prefiltering on or off for certain file types.

If a file type is associated with a guest VM image, it will be scanned if the file type enters the job queue as defined in the Scan Profile page. You can turn on FortiGuard prefiltering for a file type so that files of that type will be statically scanned first by an advanced analytic engine, and only suspicious files will be sandboxing scanned by the guest image. This can improve the system's scan performance, and all files will still go through an AV scan, a static scan, and community cloud query steps.

For the URL type, when FortiGuard prefiltering is enabled, only URLs whose web filtering rating is Unrated will be scanned inside associated guest VM image.

Syntax

sandboxing-prefilter [-h|-l|-e|-d] -t[dll|pdf|swf|js|htm|url|office|trustvendor|trustdomain|archive|trustfndr]

Option

Description

-h

Help information.

-e

Enable sandboxing prefilter.

  • -t[dll|pdf|swf|js|htm|url|office|trustvendor|trustdomain|archive|trustfndr]: Enable sandboxing prefilter for specific types.

-d

Disable sandboxing prefilter.

  • -t[dll|pdf|swf|js|htm|url|office|trustvendor|trustdomain|archive|trustfndr]: Enable sandboxing prefilter for specific types.

-l

Display the status of sandboxing prefilter.

-t

Enable/disable sandboxing prefilter for specific file types: archive, dll, pdf, swf, js, htm, url, office, trustvendor, trustdomain,trustfndr.

archive and trustdomain are enabled by default. Other prefilters are disabled by default.

When trustvendor is selected, executable files from a small internal list of trusted vendors will skip the sandboxing scan step.

When trustdomain is selected, files downloaded from a small internal list of trusted domains will skip the sandboxing scan step.

When trustfndr is selected, files rated by FortiNDR as clean or malicious will skip the sandboxing VM scan step.

trustfndr

Replace the trustfai.

sandboxing-prefilter

Allow user to turn FortiGuard prefiltering on or off for certain file types.

If a file type is associated with a guest VM image, it will be scanned if the file type enters the job queue as defined in the Scan Profile page. You can turn on FortiGuard prefiltering for a file type so that files of that type will be statically scanned first by an advanced analytic engine, and only suspicious files will be sandboxing scanned by the guest image. This can improve the system's scan performance, and all files will still go through an AV scan, a static scan, and community cloud query steps.

For the URL type, when FortiGuard prefiltering is enabled, only URLs whose web filtering rating is Unrated will be scanned inside associated guest VM image.

Syntax

sandboxing-prefilter [-h|-l|-e|-d] -t[dll|pdf|swf|js|htm|url|office|trustvendor|trustdomain|archive|trustfndr]

Option

Description

-h

Help information.

-e

Enable sandboxing prefilter.

  • -t[dll|pdf|swf|js|htm|url|office|trustvendor|trustdomain|archive|trustfndr]: Enable sandboxing prefilter for specific types.

-d

Disable sandboxing prefilter.

  • -t[dll|pdf|swf|js|htm|url|office|trustvendor|trustdomain|archive|trustfndr]: Enable sandboxing prefilter for specific types.

-l

Display the status of sandboxing prefilter.

-t

Enable/disable sandboxing prefilter for specific file types: archive, dll, pdf, swf, js, htm, url, office, trustvendor, trustdomain,trustfndr.

archive and trustdomain are enabled by default. Other prefilters are disabled by default.

When trustvendor is selected, executable files from a small internal list of trusted vendors will skip the sandboxing scan step.

When trustdomain is selected, files downloaded from a small internal list of trusted domains will skip the sandboxing scan step.

When trustfndr is selected, files rated by FortiNDR as clean or malicious will skip the sandboxing VM scan step.

trustfndr

Replace the trustfai.