
Dynamically runs suspicious files and URLs in an isolated environment, extracting malicious behavior, IOCs and sample lineage — turning "unknown samples" into "known threats."
BIG Sandbox System is BIGTON's independently developed dynamic detection product for unknown threats. Using multi-architecture virtualization, it truly detonates suspicious samples in an isolated environment, monitoring system calls, network connections and file operations throughout the run. It precisely extracts malicious behavior characteristics, IOCs (indicators of compromise) and sample lineage, leaving even the most deeply disguised unknown threat nowhere to hide.
The system builds in anti-evasion and anti-debugging countermeasures to effectively identify advanced threats such as fileless attacks and obfuscated samples. The threat intelligence produced by detection is automatically stored and feeds directly into situational awareness analysis and automatic boundary blocking, forming a closed detect – analyze – respond defense loop. Local detonation deployment is supported, so sample data never leaves your premises, fully meeting confidentiality and compliance requirements.
Multi-engine static pre-screening plus multi-architecture dynamic detonation — combining static and dynamic analysis to identify unknown threats
Supports isolated execution across x86 / ARM / mobile environments, covering diverse sample forms and faithfully reproducing the complete behavior of a sample in its target environment.
Built-in anti-sandbox detection bypass and anti-debugging techniques, complemented by manual analysis, to effectively identify fileless, obfuscated and other advanced samples with anti-analysis capabilities.
Reconstructs process, network and file behavior chains, builds behavior graphs and outputs traceable sample lineage, providing complete context for analysis.
AI-driven behavior verdicts automatically generate IOCs and threat tags, standardized to feed situational awareness and the blocking loop — detect in one place, act across the whole network.
From sample intake to intelligence output — turning dynamic behavior into consumable threat intelligence
Unified intake and pre-processing of multi-source samples from email attachments, files and URLs
Parallel static screening with antivirus signatures, YARA rules and file hashes
Isolated execution across multiple OS environments, monitoring system calls / network / file behavior
AI behavior verdict, producing IOCs, sample lineage and threat tags