BIG Sandbox System

Dynamically runs suspicious files and URLs in an isolated environment, extracting malicious behavior, IOCs and sample lineage — turning "unknown samples" into "known threats."

OVERVIEW

Product Overview

BIG Sandbox System is BIGTON's independently developed dynamic detection product for unknown threats. Using multi-architecture virtualization, it truly detonates suspicious samples in an isolated environment, monitoring system calls, network connections and file operations throughout the run. It precisely extracts malicious behavior characteristics, IOCs (indicators of compromise) and sample lineage, leaving even the most deeply disguised unknown threat nowhere to hide.

The system builds in anti-evasion and anti-debugging countermeasures to effectively identify advanced threats such as fileless attacks and obfuscated samples. The threat intelligence produced by detection is automatically stored and feeds directly into situational awareness analysis and automatic boundary blocking, forming a closed detect – analyze – respond defense loop. Local detonation deployment is supported, so sample data never leaves your premises, fully meeting confidentiality and compliance requirements.

CORE FEATURES

Core Features

Multi-engine static pre-screening plus multi-architecture dynamic detonation — combining static and dynamic analysis to identify unknown threats

01

Multi-Architecture Dynamic Detonation

Supports isolated execution across x86 / ARM / mobile environments, covering diverse sample forms and faithfully reproducing the complete behavior of a sample in its target environment.

02

Advanced Evasion Countermeasures

Built-in anti-sandbox detection bypass and anti-debugging techniques, complemented by manual analysis, to effectively identify fileless, obfuscated and other advanced samples with anti-analysis capabilities.

03

Behavior Graph & Lineage

Reconstructs process, network and file behavior chains, builds behavior graphs and outputs traceable sample lineage, providing complete context for analysis.

04

Automated Intelligence Output

AI-driven behavior verdicts automatically generate IOCs and threat tags, standardized to feed situational awareness and the blocking loop — detect in one place, act across the whole network.

HOW IT WORKS

How It Works

From sample intake to intelligence output — turning dynamic behavior into consumable threat intelligence

1

Sample Intake

Unified intake and pre-processing of multi-source samples from email attachments, files and URLs

2

Multi-Engine Static Pre-Screening

Parallel static screening with antivirus signatures, YARA rules and file hashes

3

Dynamic Detonation

Isolated execution across multiple OS environments, monitoring system calls / network / file behavior

4

Behavior Verdict & Output

AI behavior verdict, producing IOCs, sample lineage and threat tags

Closed-loop linkage: verdicts on malicious samples feed directly into the threat intelligence library, driving situational awareness analysis and automatic boundary blocking.
SCENARIOS & VALUE

Scenarios & Value

Email Attachment Inspection

Isolated detonation of inbound email attachments
  • Inbound attachments quarantined before release
  • Automatic behavior verdicts on malicious documents
  • Phishing attachments identified and blocked in seconds

Malicious Document / Payload Analysis

Reproducing the real behavior of document-borne attacks
  • Office / PDF / script behavior reconstruction
  • Fileless attacks made observable
  • Complete attack execution chain reconstructed

Threat Intelligence Production

Batch analysis of unknown samples to produce intelligence
  • Automatic IOC and threat tag generation
  • Direct feedback into blocking and situational awareness
  • Intelligence stored automatically for network-wide correlation
Dynamic Discovery
Unknown threats exposed
Automated Workload Relief
Analyst effort greatly reduced
Closed-Loop Upgrade
Intelligence feeds network-wide defense
Behavior Traceability
Forensic and compliance assurance