<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic EN: Threat Emulation &amp;amp; Extraction Deep Dive: The Sandbox Pipeline, Extract Modes &amp;amp; Zero Phishing in Endpoint</title>
    <link>https://community.checkpoint.com/t5/Endpoint/EN-Threat-Emulation-amp-Extraction-Deep-Dive-The-Sandbox/m-p/281234#M11618</link>
    <description>&lt;P&gt;&lt;EM&gt;Article 6 of the Harmony Endpoint Deep Dives series · &lt;STRONG&gt;A note on management:&lt;/STRONG&gt; Harmony Endpoint is cloud-managed (Infinity Portal / Web Management) in most deployments today. The content below follows the cloud model — Threat Emulation, Threat Extraction, Credential Protection and Files Protection all live under the unified &lt;STRONG&gt;Threat Prevention &amp;gt; Web &amp;amp; Files Protection&lt;/STRONG&gt; policy. Where an on-premises Management Server behaves differently, that is called out.&lt;/EM&gt;&lt;/P&gt;
&lt;H2&gt;Purpose&lt;/H2&gt;
&lt;P&gt;How does Harmony Endpoint let users open a downloaded document &lt;EM&gt;immediately&lt;/EM&gt; while a sandbox is still detonating the original? This article maps the full zero-day pipeline in the cloud console: the Download (web) Emulation &amp;amp; Extraction options, the per-file-type file actions, Extract Modes, the cloud emulation knobs (size limit, environments, block-on-failure), and the two Credential Protection controls (Zero Phishing and Password Reuse).&lt;/P&gt;
&lt;H2&gt;Audience&lt;/H2&gt;
&lt;UL&gt;
&lt;LI&gt;[x] Security Engineers&lt;/LI&gt;
&lt;LI&gt;[x] Endpoint Administrators&lt;/LI&gt;
&lt;LI&gt;[x] SOC Analysts&lt;/LI&gt;
&lt;LI&gt;[x] Beginners&lt;/LI&gt;
&lt;LI&gt;[&amp;nbsp; ] Experts&lt;/LI&gt;
&lt;/UL&gt;
&lt;H2&gt;Prerequisites&lt;/H2&gt;
&lt;UL&gt;
&lt;LI&gt;Threat Prevention policy basics in the &lt;STRONG&gt;Web Management&lt;/STRONG&gt; console (&lt;A href="https://community.checkpoint.com/../../architecture/01-harmony-endpoint-architecture-overview/README.md" target="_blank"&gt;Article 1&lt;/A&gt;)&lt;/LI&gt;
&lt;LI&gt;The &lt;STRONG&gt;Endpoint Security Browser Extension&lt;/STRONG&gt; installed. Download (web) Emulation &amp;amp; Extraction is supported on Chrome, Edge (Chromium), Firefox, Brave and Internet Explorer (Windows) and Chrome/Firefox/Brave/Edge (macOS) — &lt;STRONG&gt;not&lt;/STRONG&gt; on Safari&lt;/LI&gt;
&lt;/UL&gt;
&lt;HR /&gt;
&lt;H2&gt;Overview&lt;/H2&gt;
&lt;P&gt;This protection family combines cooperating engines against advanced and zero-day file-borne threats. In the cloud console they sit inside &lt;STRONG&gt;Web &amp;amp; Files Protection&lt;/STRONG&gt; (Threat Emulation, Threat Extraction, Credential Protection, Files Protection), with &lt;STRONG&gt;Anti-Exploit&lt;/STRONG&gt; under &lt;STRONG&gt;Behavioral Protection&lt;/STRONG&gt;:&lt;/P&gt;
&lt;TABLE style="border-collapse: collapse;" border="1" cellpadding="8"&gt;
&lt;THEAD&gt;
&lt;TR style="background-color: #d9e2f3;"&gt;
&lt;TD&gt;&lt;STRONG&gt;Engine&lt;/STRONG&gt;&lt;/TD&gt;
&lt;TD&gt;&lt;STRONG&gt;What it does&lt;/STRONG&gt;&lt;/TD&gt;
&lt;/TR&gt;
&lt;/THEAD&gt;
&lt;TBODY&gt;
&lt;TR&gt;
&lt;TD&gt;&lt;STRONG&gt;Threat Emulation&lt;/STRONG&gt;&lt;/TD&gt;
&lt;TD&gt;Detects zero-day and unknown attacks — files from the endpoint are sent to a &lt;STRONG&gt;sandbox&lt;/STRONG&gt; for emulation, catching evasive zero-day attacks&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD&gt;&lt;STRONG&gt;Threat Extraction&lt;/STRONG&gt;&lt;/TD&gt;
&lt;TD&gt;Proactively protects users — quickly delivers &lt;STRONG&gt;safe (sanitized) files&lt;/STRONG&gt; while the originals are inspected (Content Disarm &amp;amp; Reconstruction)&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD&gt;&lt;STRONG&gt;Anti-Exploit&lt;/STRONG&gt;&lt;/TD&gt;
&lt;TD&gt;Detects zero-day and unknown attacks and protects &lt;STRONG&gt;vulnerable processes&lt;/STRONG&gt; from exploitation (covered in depth in &lt;A href="https://community.checkpoint.com/../25-anti-exploit-deep-dive/README.md" target="_blank"&gt;Article 25&lt;/A&gt;)&lt;/TD&gt;
&lt;/TR&gt;
&lt;/TBODY&gt;
&lt;/TABLE&gt;
&lt;P&gt;The &lt;STRONG&gt;Endpoint Security Browser Extension&lt;/STRONG&gt; is the front door of the download pipeline.&lt;/P&gt;
&lt;HR /&gt;
&lt;H2&gt;The Web Download Pipeline&lt;/H2&gt;
&lt;P style="background-color: #fff3cd; padding: 10px;"&gt;&lt;STRONG&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-center" image-alt="diag1-download-pipeline.png" style="width: 604px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/35061i949DED587F8985CC/image-size/large?v=v2&amp;amp;px=999" role="button" title="diag1-download-pipeline.png" alt="diag1-download-pipeline.png" /&gt;&lt;/span&gt;&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Set the main mode under &lt;STRONG&gt;Policy &amp;gt; Threat Prevention &amp;gt; Policy Capabilities &amp;gt; Web &amp;amp; Files Protection&lt;/STRONG&gt;, in the &lt;STRONG&gt;Download (web) Emulation &amp;amp; Extraction&lt;/STRONG&gt; section:&lt;/P&gt;
&lt;OL&gt;
&lt;LI&gt;&lt;STRONG&gt;Prevent&lt;/STRONG&gt; — files are sent for emulation and extraction. This is the protective default.&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;Detect&lt;/STRONG&gt; — emulates the original without suspending access and logs the incident; the file is still blocked if it is malicious or blocked by extension.&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;Off&lt;/STRONG&gt; — no emulation or extraction; supported files are allowed.&lt;/LI&gt;
&lt;/OL&gt;
&lt;P style="background-color: #eef4fb; border-left: 4px solid #2e6da4; padding: 10px;"&gt;&lt;span class="lia-unicode-emoji" title=":information:"&gt;ℹ️&lt;/span&gt; &lt;STRONG&gt;Note:&lt;/STRONG&gt; Threat Extraction only applies to file types that can be extracted (documents); Threat Emulation only to types that can be emulated (executables, scripts, and many document formats).&lt;/P&gt;
&lt;H3&gt;Per-file-type file actions&lt;/H3&gt;
&lt;P&gt;Under &lt;STRONG&gt;Advanced Settings &amp;gt; Threat Emulation &amp;gt; Override Default File Actions &amp;gt; Edit&lt;/STRONG&gt;, choose a &lt;STRONG&gt;File action&lt;/STRONG&gt; per supported file type:&lt;/P&gt;
&lt;TABLE style="border-collapse: collapse;" border="1" cellpadding="8"&gt;
&lt;THEAD&gt;
&lt;TR style="background-color: #d9e2f3;"&gt;
&lt;TD&gt;&lt;STRONG&gt;Option&lt;/STRONG&gt;&lt;/TD&gt;
&lt;TD&gt;&lt;STRONG&gt;User experience&lt;/STRONG&gt;&lt;/TD&gt;
&lt;/TR&gt;
&lt;/THEAD&gt;
&lt;TBODY&gt;
&lt;TR&gt;
&lt;TD&gt;&lt;STRONG&gt;Prevent&lt;/STRONG&gt;&lt;/TD&gt;
&lt;TD&gt;Sent for emulation/extraction. Sub-options below decide the copy behavior&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD&gt;&lt;STRONG&gt;Allow&lt;/STRONG&gt;&lt;/TD&gt;
&lt;TD&gt;All supported files allowed without emulation (overrides Prevent)&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD&gt;&lt;STRONG&gt;Detect&lt;/STRONG&gt;&lt;/TD&gt;
&lt;TD&gt;Emulates without suspending access and logs; blocked only if malicious or blocked by extension&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD&gt;&lt;STRONG&gt;Off&lt;/STRONG&gt;&lt;/TD&gt;
&lt;TD&gt;Allow file; no emulation or extraction&lt;/TD&gt;
&lt;/TR&gt;
&lt;/TBODY&gt;
&lt;/TABLE&gt;
&lt;P&gt;When &lt;STRONG&gt;Prevent&lt;/STRONG&gt; is chosen, the copy behavior comes from the Supported Files sub-options:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;STRONG&gt;Get extracted copy before emulation completes&lt;/STRONG&gt; — the system appends &lt;CODE&gt;.cleaned&lt;/CODE&gt; to the file name and delivers it immediately (see Extract Modes below).&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;Suspend download until emulation completes&lt;/STRONG&gt; — the user waits; if benign the original is delivered, if malicious a Block page appears. More security, more delay.&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;Emulate original file without suspending access&lt;/STRONG&gt; — the original goes to the user immediately (even if it later turns out malicious).&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;For &lt;STRONG&gt;Unsupported files&lt;/STRONG&gt; (types that can be neither emulated nor extracted), go to &lt;STRONG&gt;Advanced Settings &amp;gt; Download Protection &amp;gt; Unsupported Files&lt;/STRONG&gt; and choose Allow or Block; per-extension overrides are available.&lt;/P&gt;
&lt;H3&gt;Extract Modes&lt;/H3&gt;
&lt;P&gt;When files are extracted, choose the sanitized format:&lt;/P&gt;
&lt;OL&gt;
&lt;LI&gt;&lt;STRONG&gt;Extract potential malicious elements&lt;/STRONG&gt; — same file type, with the selected malicious parts (macros, JavaScript, etc.) removed.&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;Convert to PDF&lt;/STRONG&gt; — converts the file to PDF, keeping text and formatting.&lt;/LI&gt;
&lt;/OL&gt;
&lt;P style="background-color: #eef4fb; border-left: 4px solid #2e6da4; padding: 10px;"&gt;&lt;span class="lia-unicode-emoji" title=":white_heavy_check_mark:"&gt;✅&lt;/span&gt; &lt;STRONG&gt;Best Practice (from the guide):&lt;/STRONG&gt; for PDFs in right-to-left languages or Asian fonts, prefer &lt;STRONG&gt;Extract potential malicious elements&lt;/STRONG&gt; so those files are processed correctly.&lt;/P&gt;
&lt;H3&gt;Files Protection (file system)&lt;/H3&gt;
&lt;P&gt;Beyond web downloads, &lt;STRONG&gt;Files Protection&lt;/STRONG&gt; covers files on disk, with two components:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;STRONG&gt;Anti-Malware Mode&lt;/STRONG&gt; — Prevent / Detect / Off (Detect logs but the malware stays executable — use with caution).&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;Files Threat Emulation Mode&lt;/STRONG&gt; — &lt;STRONG&gt;Prevent&lt;/STRONG&gt; (detects a malicious file, logs the event and &lt;STRONG&gt;deletes the file&lt;/STRONG&gt;), &lt;STRONG&gt;Detect&lt;/STRONG&gt; (detects and logs only), or &lt;STRONG&gt;Off&lt;/STRONG&gt;. Supported on client E86.80 and higher.&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;&lt;STRONG&gt;Logging:&lt;/STRONG&gt; Threat Emulation / Extraction events appear in the &lt;STRONG&gt;Logs&lt;/STRONG&gt; view (filter by the Threat Emulation blade). Open an event's Card to see Forensic Details (including a macro's hash for exclusions).&lt;/P&gt;
&lt;HR /&gt;
&lt;H2&gt;The Cloud Sandbox: Size, Environments &amp;amp; Fail-Handling&lt;/H2&gt;
&lt;P&gt;In the cloud model, emulation runs in Check Point's cloud sandbox. The knobs that matter are all under &lt;STRONG&gt;Advanced Settings &amp;gt; Download Protection&lt;/STRONG&gt;:&lt;/P&gt;
&lt;P style="background-color: #fff3cd; padding: 10px;"&gt;&lt;STRONG&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-center" image-alt="diag2-backend-routing.png" style="width: 999px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/35062iC1B28F4FB422C4FD/image-size/large?v=v2&amp;amp;px=999" role="button" title="diag2-backend-routing.png" alt="diag2-backend-routing.png" /&gt;&lt;/span&gt;&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;STRONG&gt;Maximum file size&lt;/STRONG&gt; (Emulation Environments &amp;gt; &lt;EM&gt;Upload and emulate files under&lt;/EM&gt;&lt;span class="lia-unicode-emoji" title=":disappointed_face:"&gt;😞&lt;/span&gt; client &lt;STRONG&gt;E86.40 and higher supports up to 100 MB&lt;/STRONG&gt;; older clients up to &lt;STRONG&gt;15 MB&lt;/STRONG&gt;. Larger limits mean more client processing and network traffic.&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;Emulation Environments:&lt;/STRONG&gt; &lt;EM&gt;Use Check Point recommended emulation environments&lt;/EM&gt; (default), or select specific OS images — the latter only when configured from &lt;STRONG&gt;SmartConsole&lt;/STRONG&gt;.&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;Block on failure:&lt;/STRONG&gt; &lt;EM&gt;Block downloads when emulation fails due to size limit or connectivity problem&lt;/EM&gt;, and &lt;EM&gt;…due to file encryption&lt;/EM&gt; — decide whether a file that can't be emulated is blocked or allowed.&lt;/LI&gt;
&lt;/UL&gt;
&lt;HR /&gt;
&lt;H2&gt;The Sandbox's Real Enemy: Evasion&lt;/H2&gt;
&lt;P&gt;A sandbox only works if the malware doesn't realize it's &lt;EM&gt;in&lt;/EM&gt; a sandbox. Modern samples check for tell-tale artifacts — &lt;EM&gt;Is there mouse movement? Real documents? Days of uptime? VM drivers?&lt;/EM&gt; — and if it smells like an analysis environment, they play dead and reveal nothing. Check Point's own research catalogs these tricks in the &lt;STRONG&gt;&lt;A href="https://evasions.checkpoint.com" target="_blank"&gt;Evasions Encyclopedia&lt;/A&gt;&lt;/STRONG&gt; and &lt;STRONG&gt;&lt;A href="https://anti-debug.checkpoint.com" target="_blank"&gt;Anti-Debug Encyclopedia&lt;/A&gt;&lt;/STRONG&gt;, and ships &lt;STRONG&gt;&lt;A href="https://github.com/CheckPointSW/InviZzzible" target="_blank"&gt;InviZzzible&lt;/A&gt;&lt;/STRONG&gt; — a tool whose entire purpose is to &lt;EM&gt;measure how detectable your sandbox is&lt;/EM&gt;.&lt;/P&gt;
&lt;P style="background-color: #eef4fb; border-left: 4px solid #2e6da4; padding: 10px;"&gt;&lt;span class="lia-unicode-emoji" title=":light_bulb:"&gt;💡&lt;/span&gt; &lt;STRONG&gt;Why this matters here:&lt;/STRONG&gt; it's the case for high-fidelity emulation. Check Point's cloud sandbox is engineered to look like a real user's machine, so evasive samples detonate instead of hiding. Emulation also runs pre-CPU-level inspection to catch exploits &lt;EM&gt;before&lt;/EM&gt; evasive logic even executes.&lt;/P&gt;
&lt;HR /&gt;
&lt;H2&gt;Exclusions That Don't Backfire&lt;/H2&gt;
&lt;P&gt;Default behavior: &lt;STRONG&gt;inspect all domains and files&lt;/STRONG&gt;. Under Web &amp;amp; Files Protection you can exclude specific &lt;STRONG&gt;folders, domains or SHA1 hashes&lt;/STRONG&gt; from Threat Emulation, Threat Extraction and Zero-Phishing.&lt;/P&gt;
&lt;P&gt;Domain rules (from the guide):&lt;/P&gt;
&lt;TABLE style="border-collapse: collapse;" border="1" cellpadding="8"&gt;
&lt;THEAD&gt;
&lt;TR style="background-color: #d9e2f3;"&gt;
&lt;TD&gt;&lt;STRONG&gt;You enter&lt;/STRONG&gt;&lt;/TD&gt;
&lt;TD&gt;&lt;STRONG&gt;Excludes&lt;/STRONG&gt;&lt;/TD&gt;
&lt;TD&gt;&lt;STRONG&gt;Does NOT exclude&lt;/STRONG&gt;&lt;/TD&gt;
&lt;/TR&gt;
&lt;/THEAD&gt;
&lt;TBODY&gt;
&lt;TR&gt;
&lt;TD&gt;&lt;CODE&gt;&lt;A href="http://www.domain.com" target="_blank"&gt;www.domain.com&lt;/A&gt;&lt;/CODE&gt;&lt;/TD&gt;
&lt;TD&gt;http/https &lt;CODE&gt;&lt;A href="http://www.domain.com" target="_blank"&gt;www.domain.com&lt;/A&gt;&lt;/CODE&gt; and &lt;CODE&gt;domain.com&lt;/CODE&gt;&lt;/TD&gt;
&lt;TD&gt;&lt;CODE&gt;sub.domain.com&lt;/CODE&gt;&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD&gt;&lt;CODE&gt;domain.com&lt;/CODE&gt;&lt;/TD&gt;
&lt;TD&gt;&lt;CODE&gt;&lt;A href="http://www.domain.com" target="_blank"&gt;www.domain.com&lt;/A&gt;&lt;/CODE&gt;, &lt;CODE&gt;domain.com&lt;/CODE&gt;, &lt;STRONG&gt;all subdomains&lt;/STRONG&gt;&lt;/TD&gt;
&lt;TD&gt;—&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD&gt;&lt;CODE&gt;sub.domain.com&lt;/CODE&gt;&lt;/TD&gt;
&lt;TD&gt;&lt;CODE&gt;sub.domain.com&lt;/CODE&gt;&lt;/TD&gt;
&lt;TD&gt;&lt;CODE&gt;sub2.domain.com&lt;/CODE&gt;&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD&gt;&lt;CODE&gt;*.domain.com&lt;/CODE&gt;&lt;/TD&gt;
&lt;TD&gt;subdomains of &lt;CODE&gt;domain.com&lt;/CODE&gt; (e.g. &lt;CODE&gt;sub1.domain.com&lt;/CODE&gt;)&lt;/TD&gt;
&lt;TD&gt;—&lt;/TD&gt;
&lt;/TR&gt;
&lt;/TBODY&gt;
&lt;/TABLE&gt;
&lt;P&gt;Rules of the road:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;Domain exclusions: &lt;STRONG&gt;no http/https or special characters except the asterisk &lt;CODE&gt;*&lt;/CODE&gt;&lt;/STRONG&gt;; with or without &lt;CODE&gt;www&lt;/CODE&gt; is fine; relevant only for the browser extension.&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;File Reputation exclusions are by SHA1&lt;/STRONG&gt; (Threat Emulation / file system monitoring); from E86.40 SHA1 also excludes downloaded files and local HTML from the extension. &lt;STRONG&gt;Macro exclusions&lt;/STRONG&gt; (by the macro's SHA1) are supported on E88.00+.&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;Folder exclusions&lt;/STRONG&gt;: Windows path, &lt;STRONG&gt;no environment variables&lt;/STRONG&gt; (e.g. &lt;CODE&gt;C:\Program Files\MyTrustedDirectory\&lt;/CODE&gt;).&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;IP&lt;/STRONG&gt; format: &lt;CODE&gt;&amp;lt;X.X.X.X&amp;gt;/&amp;lt;mask&amp;gt;&lt;/CODE&gt; (e.g. &lt;CODE&gt;192.168.100.30/24&lt;/CODE&gt;).&lt;/LI&gt;
&lt;/UL&gt;
&lt;P style="background-color: #eef4fb; border-left: 4px solid #2e6da4; padding: 10px;"&gt;&lt;span class="lia-unicode-emoji" title=":warning:"&gt;⚠️&lt;/span&gt; &lt;STRONG&gt;Warning:&lt;/STRONG&gt; excluding a parent domain silently excludes &lt;STRONG&gt;all its subdomains&lt;/STRONG&gt; — an over-broad exclusion can drop protection you didn't intend to drop.&lt;/P&gt;
&lt;HR /&gt;
&lt;H2&gt;Credential Protection: Zero Phishing + Password Reuse&lt;/H2&gt;
&lt;P&gt;Both live under &lt;STRONG&gt;Web &amp;amp; Files Protection &amp;gt; Credential Protection&lt;/STRONG&gt;.&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;1. Zero Phishing&lt;/STRONG&gt; — checks a site's characteristics to verify it is not impersonating another site to misuse personal information. Modes: &lt;STRONG&gt;Prevent&lt;/STRONG&gt; (default; user cannot access a phishing site, a log is created), &lt;STRONG&gt;Detect&lt;/STRONG&gt; (log only), &lt;STRONG&gt;Off&lt;/STRONG&gt;. Advanced options: allow the user to dismiss the phishing alert; send a log on &lt;EM&gt;every&lt;/EM&gt; scanned site; allow the user to abort scans; &lt;STRONG&gt;Scan local HTML files&lt;/STRONG&gt; (E86.50+ on Chromium browsers); disable the scan notification (the scan still runs, shown by the yellow highlight around the input field).&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;2. Password Reuse&lt;/STRONG&gt; — Endpoint Security keeps a &lt;STRONG&gt;cryptographic secure hash&lt;/STRONG&gt; of passwords used in the &lt;STRONG&gt;Protected Domains&lt;/STRONG&gt; (set via Edit &amp;gt; Protected Domains) and compares them against passwords typed elsewhere. Modes: &lt;STRONG&gt;Prevent&lt;/STRONG&gt; (default; blocks entering the corporate password on a non-corporate site), &lt;STRONG&gt;Detect&lt;/STRONG&gt; (does not block; captures it in the logs), &lt;STRONG&gt;Off&lt;/STRONG&gt;. &lt;EM&gt;Detect &amp;amp; Alert&lt;/EM&gt; exists only in older releases and is deprecated by Prevent.&lt;/P&gt;
&lt;P style="background-color: #eef4fb; border-left: 4px solid #2e6da4; padding: 10px;"&gt;&lt;span class="lia-unicode-emoji" title=":light_bulb:"&gt;💡&lt;/span&gt; &lt;STRONG&gt;Tip:&lt;/STRONG&gt; Password Reuse is one of the most underrated anti-phishing controls — it catches the exact moment credentials are about to leak, even on sites that pass every reputation check.&lt;/P&gt;
&lt;HR /&gt;
&lt;H2&gt;Best Practices&lt;/H2&gt;
&lt;P style="background-color: #eef4fb; border-left: 4px solid #2e6da4; padding: 10px;"&gt;&lt;span class="lia-unicode-emoji" title=":white_heavy_check_mark:"&gt;✅&lt;/span&gt; &lt;STRONG&gt;Best Practice:&lt;/STRONG&gt; keep &lt;STRONG&gt;Prevent&lt;/STRONG&gt; with &lt;STRONG&gt;Get extracted copy before emulation completes&lt;/STRONG&gt; for document-type downloads — users get a safe &lt;CODE&gt;.cleaned&lt;/CODE&gt; copy instantly, so security doesn't cost them waiting time.&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-unicode-emoji" title=":white_heavy_check_mark:"&gt;✅&lt;/span&gt; &lt;STRONG&gt;Best Practice:&lt;/STRONG&gt; enter domain exclusions without http/https or special characters (only &lt;CODE&gt;*&lt;/CODE&gt; is allowed), and make each exclusion as specific as the case allows.&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-unicode-emoji" title=":white_heavy_check_mark:"&gt;✅&lt;/span&gt; &lt;STRONG&gt;Best Practice:&lt;/STRONG&gt; decide the &lt;STRONG&gt;block-on-failure&lt;/STRONG&gt; behavior deliberately — for high-risk populations, block downloads that fail emulation due to size, connectivity or encryption.&lt;/P&gt;
&lt;HR /&gt;
&lt;H2&gt;Common Mistakes&lt;/H2&gt;
&lt;TABLE style="border-collapse: collapse;" border="1" cellpadding="8"&gt;
&lt;THEAD&gt;
&lt;TR style="background-color: #d9e2f3;"&gt;
&lt;TD&gt;&lt;STRONG&gt;Mistake&lt;/STRONG&gt;&lt;/TD&gt;
&lt;TD&gt;&lt;STRONG&gt;Impact&lt;/STRONG&gt;&lt;/TD&gt;
&lt;TD&gt;&lt;STRONG&gt;Solution&lt;/STRONG&gt;&lt;/TD&gt;
&lt;/TR&gt;
&lt;/THEAD&gt;
&lt;TBODY&gt;
&lt;TR&gt;
&lt;TD&gt;"Emulate original without suspending access" on risky file types&lt;/TD&gt;
&lt;TD&gt;User opens the file before the verdict&lt;/TD&gt;
&lt;TD&gt;Reserve it for low-risk categories; suspend originals for executables&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD&gt;Excluding &lt;CODE&gt;domain.com&lt;/CODE&gt; to fix one subdomain issue&lt;/TD&gt;
&lt;TD&gt;All subdomains excluded&lt;/TD&gt;
&lt;TD&gt;Exclude the specific subdomain, or use a precise pattern&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD&gt;Folder exclusion with &lt;CODE&gt;%USERPROFILE%&lt;/CODE&gt; etc.&lt;/TD&gt;
&lt;TD&gt;Not supported — exclusion doesn't work&lt;/TD&gt;
&lt;TD&gt;Use literal Windows paths&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD&gt;Assuming a "&amp;lt; 10 MB" emulation cap&lt;/TD&gt;
&lt;TD&gt;Larger files silently skip emulation on old clients&lt;/TD&gt;
&lt;TD&gt;On E86.40+ raise the limit (up to 100 MB) and set block-on-failure&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD&gt;Expecting Threat Extraction/Emulation on Safari&lt;/TD&gt;
&lt;TD&gt;Unsupported on Safari&lt;/TD&gt;
&lt;TD&gt;Use Chrome, Edge (Chromium), Firefox or Brave&lt;/TD&gt;
&lt;/TR&gt;
&lt;/TBODY&gt;
&lt;/TABLE&gt;
&lt;HR /&gt;
&lt;H2&gt;Troubleshooting&lt;/H2&gt;
&lt;P&gt;&lt;STRONG&gt;Symptom:&lt;/STRONG&gt; Users complain downloads are "stuck" for a while &lt;STRONG&gt;Environment:&lt;/STRONG&gt; Download Emulation &amp;amp; Extraction with &lt;EM&gt;Suspend download until emulation completes&lt;/EM&gt; &lt;STRONG&gt;Root Cause:&lt;/STRONG&gt; With suspend, users receive nothing until the verdict &lt;STRONG&gt;Resolution:&lt;/STRONG&gt;&lt;/P&gt;
&lt;OL&gt;
&lt;LI&gt;Switch document categories to &lt;STRONG&gt;Prevent&lt;/STRONG&gt; with &lt;STRONG&gt;Get extracted copy before emulation completes&lt;/STRONG&gt; — users get the sanitized &lt;CODE&gt;.cleaned&lt;/CODE&gt; copy immediately&lt;/LI&gt;
&lt;LI&gt;Review the per-file-type overrides for the categories generating complaints&lt;/LI&gt;
&lt;LI&gt;Confirm the file is under the emulation size limit (up to 100 MB on E86.40+) and that block-on-failure isn't blocking legitimate large files&lt;/LI&gt;
&lt;/OL&gt;
&lt;HR /&gt;
&lt;H2&gt;FAQ&lt;/H2&gt;
&lt;P&gt;&lt;STRONG&gt;Q: What does the user see while a document is being emulated?&lt;/STRONG&gt; A: With &lt;EM&gt;Get extracted copy before emulation completes&lt;/EM&gt;, a &lt;CODE&gt;.cleaned&lt;/CODE&gt; copy of the document immediately. If the original is benign, it is delivered when emulation finishes.&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Q: Which files can be extracted vs emulated?&lt;/STRONG&gt; A: Extraction applies to extractable types (documents); emulation to emulatable types (executables, scripts, many document formats). Types that support neither are handled under Unsupported Files (Allow/Block).&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Q: What are the Extract Modes?&lt;/STRONG&gt; A: &lt;EM&gt;Extract potential malicious elements&lt;/EM&gt; (same format, cleaned) or &lt;EM&gt;Convert to PDF&lt;/EM&gt;.&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Q: What is the maximum file size for emulation?&lt;/STRONG&gt; A: Up to &lt;STRONG&gt;100 MB&lt;/STRONG&gt; on client E86.40 and higher (up to 15 MB on older clients), configurable under Emulation Environments.&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Q: Which browsers support Threat Extraction &amp;amp; Emulation?&lt;/STRONG&gt; A: Chrome, Edge (Chromium), Firefox, Brave and Internet Explorer on Windows, and Chrome/Firefox/Brave/Edge on macOS. &lt;STRONG&gt;Safari does not.&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Q: Where do I see the verdict logs?&lt;/STRONG&gt; A: In the &lt;STRONG&gt;Logs&lt;/STRONG&gt; view, filtered by the Threat Emulation blade — open the event Card for Forensic Details.&lt;/P&gt;
&lt;HR /&gt;
&lt;H2&gt;Related Articles&lt;/H2&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;A href="https://community.checkpoint.com/../../anti-ransomware/02-anti-ransomware-deep-dive/README.md" target="_blank"&gt;Anti-Ransomware Deep Dive&lt;/A&gt; — Article 2 · &lt;A href="https://community.checkpoint.com/t5/Endpoint/EN-Anti-Ransomware-Deep-Dive-Honeypots-Pre-Encryption-Backup-amp/m-p/279968#M11562" target="_blank"&gt;Read on CheckMates ↗&lt;/A&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;A href="https://community.checkpoint.com/../../forensics/04-anatomy-of-a-forensics-report/README.md" target="_blank"&gt;Anatomy of a Forensics Report&lt;/A&gt; — Article 4 (Threat Emulation detections feed Forensics)&lt;/LI&gt;
&lt;LI&gt;&lt;A href="https://community.checkpoint.com/../25-anti-exploit-deep-dive/README.md" target="_blank"&gt;Anti-Exploit Deep Dive&lt;/A&gt; — Article 25&lt;/LI&gt;
&lt;/UL&gt;
&lt;HR /&gt;
&lt;H2&gt;References&lt;/H2&gt;
&lt;UL&gt;
&lt;LI&gt;Check Point Harmony Endpoint Administration Guide (cloud / Infinity Portal) — &lt;EM&gt;Configuring Endpoint Policy &amp;gt; Web &amp;amp; Files Protection&lt;/EM&gt; (Download Emulation &amp;amp; Extraction, Credential Protection, Files Protection, Exclusions)&lt;/LI&gt;
&lt;LI&gt;Check Point Harmony Endpoint Administration Guide (cloud / Infinity Portal) — &lt;EM&gt;Supported Browsers for the Browser Extension&lt;/EM&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;HR /&gt;
&lt;H2&gt;Revision History&lt;/H2&gt;
&lt;TABLE style="border-collapse: collapse;" border="1" cellpadding="8"&gt;
&lt;THEAD&gt;
&lt;TR style="background-color: #d9e2f3;"&gt;
&lt;TD&gt;&lt;STRONG&gt;Date&lt;/STRONG&gt;&lt;/TD&gt;
&lt;TD&gt;&lt;STRONG&gt;Version&lt;/STRONG&gt;&lt;/TD&gt;
&lt;TD&gt;&lt;STRONG&gt;Author&lt;/STRONG&gt;&lt;/TD&gt;
&lt;TD&gt;&lt;STRONG&gt;Changes&lt;/STRONG&gt;&lt;/TD&gt;
&lt;/TR&gt;
&lt;/THEAD&gt;
&lt;TBODY&gt;
&lt;TR&gt;
&lt;TD&gt;2026-07-16&lt;/TD&gt;
&lt;TD&gt;1.0&lt;/TD&gt;
&lt;TD&gt;Jorge Luiz&lt;/TD&gt;
&lt;TD&gt;Initial version&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD&gt;2026-07-30&lt;/TD&gt;
&lt;TD&gt;2.0&lt;/TD&gt;
&lt;TD&gt;Jorge Luiz&lt;/TD&gt;
&lt;TD&gt;Cloud-first revalidation against the cloud Administration Guide: Web &amp;amp; Files Protection paths, cloud file actions (Prevent/Detect/Off + sub-options), Files Threat Emulation Mode, cloud sandbox knobs (size up to 100 MB, environments, block-on-failure), multi-browser support, &lt;CODE&gt;*&lt;/CODE&gt; in domain exclusions, Logs view; removed on-prem SmartEndpoint/SmartLog, Harmony Appliance IP/certificate and sk116381, and the unsourced "&amp;lt; 10 MB" cap&lt;/TD&gt;
&lt;/TR&gt;
&lt;/TBODY&gt;
&lt;/TABLE&gt;
&lt;HR /&gt;
&lt;P&gt;&lt;STRONG&gt;Supported Versions:&lt;/STRONG&gt; Harmony Endpoint cloud management (Infinity Portal / Web Management), Windows and macOS clients, supported browser extension &lt;STRONG&gt;Last Updated:&lt;/STRONG&gt; 2026-07-30&lt;/P&gt;
&lt;DIV id="gtx-trans" style="position: absolute; left: 670px; top: 3551.71px;"&gt;
&lt;DIV class="gtx-trans-icon"&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;/DIV&gt;</description>
    <pubDate>Tue, 18 Aug 2026 19:53:48 GMT</pubDate>
    <dc:creator>jorgeluiznim</dc:creator>
    <dc:date>2026-08-18T19:53:48Z</dc:date>
    <item>
      <title>EN: Threat Emulation &amp; Extraction Deep Dive: The Sandbox Pipeline, Extract Modes &amp; Zero Phishing</title>
      <link>https://community.checkpoint.com/t5/Endpoint/EN-Threat-Emulation-amp-Extraction-Deep-Dive-The-Sandbox/m-p/281234#M11618</link>
      <description>&lt;P&gt;&lt;EM&gt;Article 6 of the Harmony Endpoint Deep Dives series · &lt;STRONG&gt;A note on management:&lt;/STRONG&gt; Harmony Endpoint is cloud-managed (Infinity Portal / Web Management) in most deployments today. The content below follows the cloud model — Threat Emulation, Threat Extraction, Credential Protection and Files Protection all live under the unified &lt;STRONG&gt;Threat Prevention &amp;gt; Web &amp;amp; Files Protection&lt;/STRONG&gt; policy. Where an on-premises Management Server behaves differently, that is called out.&lt;/EM&gt;&lt;/P&gt;
&lt;H2&gt;Purpose&lt;/H2&gt;
&lt;P&gt;How does Harmony Endpoint let users open a downloaded document &lt;EM&gt;immediately&lt;/EM&gt; while a sandbox is still detonating the original? This article maps the full zero-day pipeline in the cloud console: the Download (web) Emulation &amp;amp; Extraction options, the per-file-type file actions, Extract Modes, the cloud emulation knobs (size limit, environments, block-on-failure), and the two Credential Protection controls (Zero Phishing and Password Reuse).&lt;/P&gt;
&lt;H2&gt;Audience&lt;/H2&gt;
&lt;UL&gt;
&lt;LI&gt;[x] Security Engineers&lt;/LI&gt;
&lt;LI&gt;[x] Endpoint Administrators&lt;/LI&gt;
&lt;LI&gt;[x] SOC Analysts&lt;/LI&gt;
&lt;LI&gt;[x] Beginners&lt;/LI&gt;
&lt;LI&gt;[&amp;nbsp; ] Experts&lt;/LI&gt;
&lt;/UL&gt;
&lt;H2&gt;Prerequisites&lt;/H2&gt;
&lt;UL&gt;
&lt;LI&gt;Threat Prevention policy basics in the &lt;STRONG&gt;Web Management&lt;/STRONG&gt; console (&lt;A href="https://community.checkpoint.com/../../architecture/01-harmony-endpoint-architecture-overview/README.md" target="_blank"&gt;Article 1&lt;/A&gt;)&lt;/LI&gt;
&lt;LI&gt;The &lt;STRONG&gt;Endpoint Security Browser Extension&lt;/STRONG&gt; installed. Download (web) Emulation &amp;amp; Extraction is supported on Chrome, Edge (Chromium), Firefox, Brave and Internet Explorer (Windows) and Chrome/Firefox/Brave/Edge (macOS) — &lt;STRONG&gt;not&lt;/STRONG&gt; on Safari&lt;/LI&gt;
&lt;/UL&gt;
&lt;HR /&gt;
&lt;H2&gt;Overview&lt;/H2&gt;
&lt;P&gt;This protection family combines cooperating engines against advanced and zero-day file-borne threats. In the cloud console they sit inside &lt;STRONG&gt;Web &amp;amp; Files Protection&lt;/STRONG&gt; (Threat Emulation, Threat Extraction, Credential Protection, Files Protection), with &lt;STRONG&gt;Anti-Exploit&lt;/STRONG&gt; under &lt;STRONG&gt;Behavioral Protection&lt;/STRONG&gt;:&lt;/P&gt;
&lt;TABLE style="border-collapse: collapse;" border="1" cellpadding="8"&gt;
&lt;THEAD&gt;
&lt;TR style="background-color: #d9e2f3;"&gt;
&lt;TD&gt;&lt;STRONG&gt;Engine&lt;/STRONG&gt;&lt;/TD&gt;
&lt;TD&gt;&lt;STRONG&gt;What it does&lt;/STRONG&gt;&lt;/TD&gt;
&lt;/TR&gt;
&lt;/THEAD&gt;
&lt;TBODY&gt;
&lt;TR&gt;
&lt;TD&gt;&lt;STRONG&gt;Threat Emulation&lt;/STRONG&gt;&lt;/TD&gt;
&lt;TD&gt;Detects zero-day and unknown attacks — files from the endpoint are sent to a &lt;STRONG&gt;sandbox&lt;/STRONG&gt; for emulation, catching evasive zero-day attacks&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD&gt;&lt;STRONG&gt;Threat Extraction&lt;/STRONG&gt;&lt;/TD&gt;
&lt;TD&gt;Proactively protects users — quickly delivers &lt;STRONG&gt;safe (sanitized) files&lt;/STRONG&gt; while the originals are inspected (Content Disarm &amp;amp; Reconstruction)&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD&gt;&lt;STRONG&gt;Anti-Exploit&lt;/STRONG&gt;&lt;/TD&gt;
&lt;TD&gt;Detects zero-day and unknown attacks and protects &lt;STRONG&gt;vulnerable processes&lt;/STRONG&gt; from exploitation (covered in depth in &lt;A href="https://community.checkpoint.com/../25-anti-exploit-deep-dive/README.md" target="_blank"&gt;Article 25&lt;/A&gt;)&lt;/TD&gt;
&lt;/TR&gt;
&lt;/TBODY&gt;
&lt;/TABLE&gt;
&lt;P&gt;The &lt;STRONG&gt;Endpoint Security Browser Extension&lt;/STRONG&gt; is the front door of the download pipeline.&lt;/P&gt;
&lt;HR /&gt;
&lt;H2&gt;The Web Download Pipeline&lt;/H2&gt;
&lt;P style="background-color: #fff3cd; padding: 10px;"&gt;&lt;STRONG&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-center" image-alt="diag1-download-pipeline.png" style="width: 604px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/35061i949DED587F8985CC/image-size/large?v=v2&amp;amp;px=999" role="button" title="diag1-download-pipeline.png" alt="diag1-download-pipeline.png" /&gt;&lt;/span&gt;&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Set the main mode under &lt;STRONG&gt;Policy &amp;gt; Threat Prevention &amp;gt; Policy Capabilities &amp;gt; Web &amp;amp; Files Protection&lt;/STRONG&gt;, in the &lt;STRONG&gt;Download (web) Emulation &amp;amp; Extraction&lt;/STRONG&gt; section:&lt;/P&gt;
&lt;OL&gt;
&lt;LI&gt;&lt;STRONG&gt;Prevent&lt;/STRONG&gt; — files are sent for emulation and extraction. This is the protective default.&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;Detect&lt;/STRONG&gt; — emulates the original without suspending access and logs the incident; the file is still blocked if it is malicious or blocked by extension.&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;Off&lt;/STRONG&gt; — no emulation or extraction; supported files are allowed.&lt;/LI&gt;
&lt;/OL&gt;
&lt;P style="background-color: #eef4fb; border-left: 4px solid #2e6da4; padding: 10px;"&gt;&lt;span class="lia-unicode-emoji" title=":information:"&gt;ℹ️&lt;/span&gt; &lt;STRONG&gt;Note:&lt;/STRONG&gt; Threat Extraction only applies to file types that can be extracted (documents); Threat Emulation only to types that can be emulated (executables, scripts, and many document formats).&lt;/P&gt;
&lt;H3&gt;Per-file-type file actions&lt;/H3&gt;
&lt;P&gt;Under &lt;STRONG&gt;Advanced Settings &amp;gt; Threat Emulation &amp;gt; Override Default File Actions &amp;gt; Edit&lt;/STRONG&gt;, choose a &lt;STRONG&gt;File action&lt;/STRONG&gt; per supported file type:&lt;/P&gt;
&lt;TABLE style="border-collapse: collapse;" border="1" cellpadding="8"&gt;
&lt;THEAD&gt;
&lt;TR style="background-color: #d9e2f3;"&gt;
&lt;TD&gt;&lt;STRONG&gt;Option&lt;/STRONG&gt;&lt;/TD&gt;
&lt;TD&gt;&lt;STRONG&gt;User experience&lt;/STRONG&gt;&lt;/TD&gt;
&lt;/TR&gt;
&lt;/THEAD&gt;
&lt;TBODY&gt;
&lt;TR&gt;
&lt;TD&gt;&lt;STRONG&gt;Prevent&lt;/STRONG&gt;&lt;/TD&gt;
&lt;TD&gt;Sent for emulation/extraction. Sub-options below decide the copy behavior&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD&gt;&lt;STRONG&gt;Allow&lt;/STRONG&gt;&lt;/TD&gt;
&lt;TD&gt;All supported files allowed without emulation (overrides Prevent)&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD&gt;&lt;STRONG&gt;Detect&lt;/STRONG&gt;&lt;/TD&gt;
&lt;TD&gt;Emulates without suspending access and logs; blocked only if malicious or blocked by extension&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD&gt;&lt;STRONG&gt;Off&lt;/STRONG&gt;&lt;/TD&gt;
&lt;TD&gt;Allow file; no emulation or extraction&lt;/TD&gt;
&lt;/TR&gt;
&lt;/TBODY&gt;
&lt;/TABLE&gt;
&lt;P&gt;When &lt;STRONG&gt;Prevent&lt;/STRONG&gt; is chosen, the copy behavior comes from the Supported Files sub-options:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;STRONG&gt;Get extracted copy before emulation completes&lt;/STRONG&gt; — the system appends &lt;CODE&gt;.cleaned&lt;/CODE&gt; to the file name and delivers it immediately (see Extract Modes below).&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;Suspend download until emulation completes&lt;/STRONG&gt; — the user waits; if benign the original is delivered, if malicious a Block page appears. More security, more delay.&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;Emulate original file without suspending access&lt;/STRONG&gt; — the original goes to the user immediately (even if it later turns out malicious).&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;For &lt;STRONG&gt;Unsupported files&lt;/STRONG&gt; (types that can be neither emulated nor extracted), go to &lt;STRONG&gt;Advanced Settings &amp;gt; Download Protection &amp;gt; Unsupported Files&lt;/STRONG&gt; and choose Allow or Block; per-extension overrides are available.&lt;/P&gt;
&lt;H3&gt;Extract Modes&lt;/H3&gt;
&lt;P&gt;When files are extracted, choose the sanitized format:&lt;/P&gt;
&lt;OL&gt;
&lt;LI&gt;&lt;STRONG&gt;Extract potential malicious elements&lt;/STRONG&gt; — same file type, with the selected malicious parts (macros, JavaScript, etc.) removed.&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;Convert to PDF&lt;/STRONG&gt; — converts the file to PDF, keeping text and formatting.&lt;/LI&gt;
&lt;/OL&gt;
&lt;P style="background-color: #eef4fb; border-left: 4px solid #2e6da4; padding: 10px;"&gt;&lt;span class="lia-unicode-emoji" title=":white_heavy_check_mark:"&gt;✅&lt;/span&gt; &lt;STRONG&gt;Best Practice (from the guide):&lt;/STRONG&gt; for PDFs in right-to-left languages or Asian fonts, prefer &lt;STRONG&gt;Extract potential malicious elements&lt;/STRONG&gt; so those files are processed correctly.&lt;/P&gt;
&lt;H3&gt;Files Protection (file system)&lt;/H3&gt;
&lt;P&gt;Beyond web downloads, &lt;STRONG&gt;Files Protection&lt;/STRONG&gt; covers files on disk, with two components:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;STRONG&gt;Anti-Malware Mode&lt;/STRONG&gt; — Prevent / Detect / Off (Detect logs but the malware stays executable — use with caution).&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;Files Threat Emulation Mode&lt;/STRONG&gt; — &lt;STRONG&gt;Prevent&lt;/STRONG&gt; (detects a malicious file, logs the event and &lt;STRONG&gt;deletes the file&lt;/STRONG&gt;), &lt;STRONG&gt;Detect&lt;/STRONG&gt; (detects and logs only), or &lt;STRONG&gt;Off&lt;/STRONG&gt;. Supported on client E86.80 and higher.&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;&lt;STRONG&gt;Logging:&lt;/STRONG&gt; Threat Emulation / Extraction events appear in the &lt;STRONG&gt;Logs&lt;/STRONG&gt; view (filter by the Threat Emulation blade). Open an event's Card to see Forensic Details (including a macro's hash for exclusions).&lt;/P&gt;
&lt;HR /&gt;
&lt;H2&gt;The Cloud Sandbox: Size, Environments &amp;amp; Fail-Handling&lt;/H2&gt;
&lt;P&gt;In the cloud model, emulation runs in Check Point's cloud sandbox. The knobs that matter are all under &lt;STRONG&gt;Advanced Settings &amp;gt; Download Protection&lt;/STRONG&gt;:&lt;/P&gt;
&lt;P style="background-color: #fff3cd; padding: 10px;"&gt;&lt;STRONG&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-center" image-alt="diag2-backend-routing.png" style="width: 999px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/35062iC1B28F4FB422C4FD/image-size/large?v=v2&amp;amp;px=999" role="button" title="diag2-backend-routing.png" alt="diag2-backend-routing.png" /&gt;&lt;/span&gt;&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;STRONG&gt;Maximum file size&lt;/STRONG&gt; (Emulation Environments &amp;gt; &lt;EM&gt;Upload and emulate files under&lt;/EM&gt;&lt;span class="lia-unicode-emoji" title=":disappointed_face:"&gt;😞&lt;/span&gt; client &lt;STRONG&gt;E86.40 and higher supports up to 100 MB&lt;/STRONG&gt;; older clients up to &lt;STRONG&gt;15 MB&lt;/STRONG&gt;. Larger limits mean more client processing and network traffic.&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;Emulation Environments:&lt;/STRONG&gt; &lt;EM&gt;Use Check Point recommended emulation environments&lt;/EM&gt; (default), or select specific OS images — the latter only when configured from &lt;STRONG&gt;SmartConsole&lt;/STRONG&gt;.&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;Block on failure:&lt;/STRONG&gt; &lt;EM&gt;Block downloads when emulation fails due to size limit or connectivity problem&lt;/EM&gt;, and &lt;EM&gt;…due to file encryption&lt;/EM&gt; — decide whether a file that can't be emulated is blocked or allowed.&lt;/LI&gt;
&lt;/UL&gt;
&lt;HR /&gt;
&lt;H2&gt;The Sandbox's Real Enemy: Evasion&lt;/H2&gt;
&lt;P&gt;A sandbox only works if the malware doesn't realize it's &lt;EM&gt;in&lt;/EM&gt; a sandbox. Modern samples check for tell-tale artifacts — &lt;EM&gt;Is there mouse movement? Real documents? Days of uptime? VM drivers?&lt;/EM&gt; — and if it smells like an analysis environment, they play dead and reveal nothing. Check Point's own research catalogs these tricks in the &lt;STRONG&gt;&lt;A href="https://evasions.checkpoint.com" target="_blank"&gt;Evasions Encyclopedia&lt;/A&gt;&lt;/STRONG&gt; and &lt;STRONG&gt;&lt;A href="https://anti-debug.checkpoint.com" target="_blank"&gt;Anti-Debug Encyclopedia&lt;/A&gt;&lt;/STRONG&gt;, and ships &lt;STRONG&gt;&lt;A href="https://github.com/CheckPointSW/InviZzzible" target="_blank"&gt;InviZzzible&lt;/A&gt;&lt;/STRONG&gt; — a tool whose entire purpose is to &lt;EM&gt;measure how detectable your sandbox is&lt;/EM&gt;.&lt;/P&gt;
&lt;P style="background-color: #eef4fb; border-left: 4px solid #2e6da4; padding: 10px;"&gt;&lt;span class="lia-unicode-emoji" title=":light_bulb:"&gt;💡&lt;/span&gt; &lt;STRONG&gt;Why this matters here:&lt;/STRONG&gt; it's the case for high-fidelity emulation. Check Point's cloud sandbox is engineered to look like a real user's machine, so evasive samples detonate instead of hiding. Emulation also runs pre-CPU-level inspection to catch exploits &lt;EM&gt;before&lt;/EM&gt; evasive logic even executes.&lt;/P&gt;
&lt;HR /&gt;
&lt;H2&gt;Exclusions That Don't Backfire&lt;/H2&gt;
&lt;P&gt;Default behavior: &lt;STRONG&gt;inspect all domains and files&lt;/STRONG&gt;. Under Web &amp;amp; Files Protection you can exclude specific &lt;STRONG&gt;folders, domains or SHA1 hashes&lt;/STRONG&gt; from Threat Emulation, Threat Extraction and Zero-Phishing.&lt;/P&gt;
&lt;P&gt;Domain rules (from the guide):&lt;/P&gt;
&lt;TABLE style="border-collapse: collapse;" border="1" cellpadding="8"&gt;
&lt;THEAD&gt;
&lt;TR style="background-color: #d9e2f3;"&gt;
&lt;TD&gt;&lt;STRONG&gt;You enter&lt;/STRONG&gt;&lt;/TD&gt;
&lt;TD&gt;&lt;STRONG&gt;Excludes&lt;/STRONG&gt;&lt;/TD&gt;
&lt;TD&gt;&lt;STRONG&gt;Does NOT exclude&lt;/STRONG&gt;&lt;/TD&gt;
&lt;/TR&gt;
&lt;/THEAD&gt;
&lt;TBODY&gt;
&lt;TR&gt;
&lt;TD&gt;&lt;CODE&gt;&lt;A href="http://www.domain.com" target="_blank"&gt;www.domain.com&lt;/A&gt;&lt;/CODE&gt;&lt;/TD&gt;
&lt;TD&gt;http/https &lt;CODE&gt;&lt;A href="http://www.domain.com" target="_blank"&gt;www.domain.com&lt;/A&gt;&lt;/CODE&gt; and &lt;CODE&gt;domain.com&lt;/CODE&gt;&lt;/TD&gt;
&lt;TD&gt;&lt;CODE&gt;sub.domain.com&lt;/CODE&gt;&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD&gt;&lt;CODE&gt;domain.com&lt;/CODE&gt;&lt;/TD&gt;
&lt;TD&gt;&lt;CODE&gt;&lt;A href="http://www.domain.com" target="_blank"&gt;www.domain.com&lt;/A&gt;&lt;/CODE&gt;, &lt;CODE&gt;domain.com&lt;/CODE&gt;, &lt;STRONG&gt;all subdomains&lt;/STRONG&gt;&lt;/TD&gt;
&lt;TD&gt;—&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD&gt;&lt;CODE&gt;sub.domain.com&lt;/CODE&gt;&lt;/TD&gt;
&lt;TD&gt;&lt;CODE&gt;sub.domain.com&lt;/CODE&gt;&lt;/TD&gt;
&lt;TD&gt;&lt;CODE&gt;sub2.domain.com&lt;/CODE&gt;&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD&gt;&lt;CODE&gt;*.domain.com&lt;/CODE&gt;&lt;/TD&gt;
&lt;TD&gt;subdomains of &lt;CODE&gt;domain.com&lt;/CODE&gt; (e.g. &lt;CODE&gt;sub1.domain.com&lt;/CODE&gt;)&lt;/TD&gt;
&lt;TD&gt;—&lt;/TD&gt;
&lt;/TR&gt;
&lt;/TBODY&gt;
&lt;/TABLE&gt;
&lt;P&gt;Rules of the road:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;Domain exclusions: &lt;STRONG&gt;no http/https or special characters except the asterisk &lt;CODE&gt;*&lt;/CODE&gt;&lt;/STRONG&gt;; with or without &lt;CODE&gt;www&lt;/CODE&gt; is fine; relevant only for the browser extension.&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;File Reputation exclusions are by SHA1&lt;/STRONG&gt; (Threat Emulation / file system monitoring); from E86.40 SHA1 also excludes downloaded files and local HTML from the extension. &lt;STRONG&gt;Macro exclusions&lt;/STRONG&gt; (by the macro's SHA1) are supported on E88.00+.&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;Folder exclusions&lt;/STRONG&gt;: Windows path, &lt;STRONG&gt;no environment variables&lt;/STRONG&gt; (e.g. &lt;CODE&gt;C:\Program Files\MyTrustedDirectory\&lt;/CODE&gt;).&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;IP&lt;/STRONG&gt; format: &lt;CODE&gt;&amp;lt;X.X.X.X&amp;gt;/&amp;lt;mask&amp;gt;&lt;/CODE&gt; (e.g. &lt;CODE&gt;192.168.100.30/24&lt;/CODE&gt;).&lt;/LI&gt;
&lt;/UL&gt;
&lt;P style="background-color: #eef4fb; border-left: 4px solid #2e6da4; padding: 10px;"&gt;&lt;span class="lia-unicode-emoji" title=":warning:"&gt;⚠️&lt;/span&gt; &lt;STRONG&gt;Warning:&lt;/STRONG&gt; excluding a parent domain silently excludes &lt;STRONG&gt;all its subdomains&lt;/STRONG&gt; — an over-broad exclusion can drop protection you didn't intend to drop.&lt;/P&gt;
&lt;HR /&gt;
&lt;H2&gt;Credential Protection: Zero Phishing + Password Reuse&lt;/H2&gt;
&lt;P&gt;Both live under &lt;STRONG&gt;Web &amp;amp; Files Protection &amp;gt; Credential Protection&lt;/STRONG&gt;.&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;1. Zero Phishing&lt;/STRONG&gt; — checks a site's characteristics to verify it is not impersonating another site to misuse personal information. Modes: &lt;STRONG&gt;Prevent&lt;/STRONG&gt; (default; user cannot access a phishing site, a log is created), &lt;STRONG&gt;Detect&lt;/STRONG&gt; (log only), &lt;STRONG&gt;Off&lt;/STRONG&gt;. Advanced options: allow the user to dismiss the phishing alert; send a log on &lt;EM&gt;every&lt;/EM&gt; scanned site; allow the user to abort scans; &lt;STRONG&gt;Scan local HTML files&lt;/STRONG&gt; (E86.50+ on Chromium browsers); disable the scan notification (the scan still runs, shown by the yellow highlight around the input field).&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;2. Password Reuse&lt;/STRONG&gt; — Endpoint Security keeps a &lt;STRONG&gt;cryptographic secure hash&lt;/STRONG&gt; of passwords used in the &lt;STRONG&gt;Protected Domains&lt;/STRONG&gt; (set via Edit &amp;gt; Protected Domains) and compares them against passwords typed elsewhere. Modes: &lt;STRONG&gt;Prevent&lt;/STRONG&gt; (default; blocks entering the corporate password on a non-corporate site), &lt;STRONG&gt;Detect&lt;/STRONG&gt; (does not block; captures it in the logs), &lt;STRONG&gt;Off&lt;/STRONG&gt;. &lt;EM&gt;Detect &amp;amp; Alert&lt;/EM&gt; exists only in older releases and is deprecated by Prevent.&lt;/P&gt;
&lt;P style="background-color: #eef4fb; border-left: 4px solid #2e6da4; padding: 10px;"&gt;&lt;span class="lia-unicode-emoji" title=":light_bulb:"&gt;💡&lt;/span&gt; &lt;STRONG&gt;Tip:&lt;/STRONG&gt; Password Reuse is one of the most underrated anti-phishing controls — it catches the exact moment credentials are about to leak, even on sites that pass every reputation check.&lt;/P&gt;
&lt;HR /&gt;
&lt;H2&gt;Best Practices&lt;/H2&gt;
&lt;P style="background-color: #eef4fb; border-left: 4px solid #2e6da4; padding: 10px;"&gt;&lt;span class="lia-unicode-emoji" title=":white_heavy_check_mark:"&gt;✅&lt;/span&gt; &lt;STRONG&gt;Best Practice:&lt;/STRONG&gt; keep &lt;STRONG&gt;Prevent&lt;/STRONG&gt; with &lt;STRONG&gt;Get extracted copy before emulation completes&lt;/STRONG&gt; for document-type downloads — users get a safe &lt;CODE&gt;.cleaned&lt;/CODE&gt; copy instantly, so security doesn't cost them waiting time.&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-unicode-emoji" title=":white_heavy_check_mark:"&gt;✅&lt;/span&gt; &lt;STRONG&gt;Best Practice:&lt;/STRONG&gt; enter domain exclusions without http/https or special characters (only &lt;CODE&gt;*&lt;/CODE&gt; is allowed), and make each exclusion as specific as the case allows.&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-unicode-emoji" title=":white_heavy_check_mark:"&gt;✅&lt;/span&gt; &lt;STRONG&gt;Best Practice:&lt;/STRONG&gt; decide the &lt;STRONG&gt;block-on-failure&lt;/STRONG&gt; behavior deliberately — for high-risk populations, block downloads that fail emulation due to size, connectivity or encryption.&lt;/P&gt;
&lt;HR /&gt;
&lt;H2&gt;Common Mistakes&lt;/H2&gt;
&lt;TABLE style="border-collapse: collapse;" border="1" cellpadding="8"&gt;
&lt;THEAD&gt;
&lt;TR style="background-color: #d9e2f3;"&gt;
&lt;TD&gt;&lt;STRONG&gt;Mistake&lt;/STRONG&gt;&lt;/TD&gt;
&lt;TD&gt;&lt;STRONG&gt;Impact&lt;/STRONG&gt;&lt;/TD&gt;
&lt;TD&gt;&lt;STRONG&gt;Solution&lt;/STRONG&gt;&lt;/TD&gt;
&lt;/TR&gt;
&lt;/THEAD&gt;
&lt;TBODY&gt;
&lt;TR&gt;
&lt;TD&gt;"Emulate original without suspending access" on risky file types&lt;/TD&gt;
&lt;TD&gt;User opens the file before the verdict&lt;/TD&gt;
&lt;TD&gt;Reserve it for low-risk categories; suspend originals for executables&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD&gt;Excluding &lt;CODE&gt;domain.com&lt;/CODE&gt; to fix one subdomain issue&lt;/TD&gt;
&lt;TD&gt;All subdomains excluded&lt;/TD&gt;
&lt;TD&gt;Exclude the specific subdomain, or use a precise pattern&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD&gt;Folder exclusion with &lt;CODE&gt;%USERPROFILE%&lt;/CODE&gt; etc.&lt;/TD&gt;
&lt;TD&gt;Not supported — exclusion doesn't work&lt;/TD&gt;
&lt;TD&gt;Use literal Windows paths&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD&gt;Assuming a "&amp;lt; 10 MB" emulation cap&lt;/TD&gt;
&lt;TD&gt;Larger files silently skip emulation on old clients&lt;/TD&gt;
&lt;TD&gt;On E86.40+ raise the limit (up to 100 MB) and set block-on-failure&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD&gt;Expecting Threat Extraction/Emulation on Safari&lt;/TD&gt;
&lt;TD&gt;Unsupported on Safari&lt;/TD&gt;
&lt;TD&gt;Use Chrome, Edge (Chromium), Firefox or Brave&lt;/TD&gt;
&lt;/TR&gt;
&lt;/TBODY&gt;
&lt;/TABLE&gt;
&lt;HR /&gt;
&lt;H2&gt;Troubleshooting&lt;/H2&gt;
&lt;P&gt;&lt;STRONG&gt;Symptom:&lt;/STRONG&gt; Users complain downloads are "stuck" for a while &lt;STRONG&gt;Environment:&lt;/STRONG&gt; Download Emulation &amp;amp; Extraction with &lt;EM&gt;Suspend download until emulation completes&lt;/EM&gt; &lt;STRONG&gt;Root Cause:&lt;/STRONG&gt; With suspend, users receive nothing until the verdict &lt;STRONG&gt;Resolution:&lt;/STRONG&gt;&lt;/P&gt;
&lt;OL&gt;
&lt;LI&gt;Switch document categories to &lt;STRONG&gt;Prevent&lt;/STRONG&gt; with &lt;STRONG&gt;Get extracted copy before emulation completes&lt;/STRONG&gt; — users get the sanitized &lt;CODE&gt;.cleaned&lt;/CODE&gt; copy immediately&lt;/LI&gt;
&lt;LI&gt;Review the per-file-type overrides for the categories generating complaints&lt;/LI&gt;
&lt;LI&gt;Confirm the file is under the emulation size limit (up to 100 MB on E86.40+) and that block-on-failure isn't blocking legitimate large files&lt;/LI&gt;
&lt;/OL&gt;
&lt;HR /&gt;
&lt;H2&gt;FAQ&lt;/H2&gt;
&lt;P&gt;&lt;STRONG&gt;Q: What does the user see while a document is being emulated?&lt;/STRONG&gt; A: With &lt;EM&gt;Get extracted copy before emulation completes&lt;/EM&gt;, a &lt;CODE&gt;.cleaned&lt;/CODE&gt; copy of the document immediately. If the original is benign, it is delivered when emulation finishes.&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Q: Which files can be extracted vs emulated?&lt;/STRONG&gt; A: Extraction applies to extractable types (documents); emulation to emulatable types (executables, scripts, many document formats). Types that support neither are handled under Unsupported Files (Allow/Block).&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Q: What are the Extract Modes?&lt;/STRONG&gt; A: &lt;EM&gt;Extract potential malicious elements&lt;/EM&gt; (same format, cleaned) or &lt;EM&gt;Convert to PDF&lt;/EM&gt;.&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Q: What is the maximum file size for emulation?&lt;/STRONG&gt; A: Up to &lt;STRONG&gt;100 MB&lt;/STRONG&gt; on client E86.40 and higher (up to 15 MB on older clients), configurable under Emulation Environments.&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Q: Which browsers support Threat Extraction &amp;amp; Emulation?&lt;/STRONG&gt; A: Chrome, Edge (Chromium), Firefox, Brave and Internet Explorer on Windows, and Chrome/Firefox/Brave/Edge on macOS. &lt;STRONG&gt;Safari does not.&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Q: Where do I see the verdict logs?&lt;/STRONG&gt; A: In the &lt;STRONG&gt;Logs&lt;/STRONG&gt; view, filtered by the Threat Emulation blade — open the event Card for Forensic Details.&lt;/P&gt;
&lt;HR /&gt;
&lt;H2&gt;Related Articles&lt;/H2&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;A href="https://community.checkpoint.com/../../anti-ransomware/02-anti-ransomware-deep-dive/README.md" target="_blank"&gt;Anti-Ransomware Deep Dive&lt;/A&gt; — Article 2 · &lt;A href="https://community.checkpoint.com/t5/Endpoint/EN-Anti-Ransomware-Deep-Dive-Honeypots-Pre-Encryption-Backup-amp/m-p/279968#M11562" target="_blank"&gt;Read on CheckMates ↗&lt;/A&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;A href="https://community.checkpoint.com/../../forensics/04-anatomy-of-a-forensics-report/README.md" target="_blank"&gt;Anatomy of a Forensics Report&lt;/A&gt; — Article 4 (Threat Emulation detections feed Forensics)&lt;/LI&gt;
&lt;LI&gt;&lt;A href="https://community.checkpoint.com/../25-anti-exploit-deep-dive/README.md" target="_blank"&gt;Anti-Exploit Deep Dive&lt;/A&gt; — Article 25&lt;/LI&gt;
&lt;/UL&gt;
&lt;HR /&gt;
&lt;H2&gt;References&lt;/H2&gt;
&lt;UL&gt;
&lt;LI&gt;Check Point Harmony Endpoint Administration Guide (cloud / Infinity Portal) — &lt;EM&gt;Configuring Endpoint Policy &amp;gt; Web &amp;amp; Files Protection&lt;/EM&gt; (Download Emulation &amp;amp; Extraction, Credential Protection, Files Protection, Exclusions)&lt;/LI&gt;
&lt;LI&gt;Check Point Harmony Endpoint Administration Guide (cloud / Infinity Portal) — &lt;EM&gt;Supported Browsers for the Browser Extension&lt;/EM&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;HR /&gt;
&lt;H2&gt;Revision History&lt;/H2&gt;
&lt;TABLE style="border-collapse: collapse;" border="1" cellpadding="8"&gt;
&lt;THEAD&gt;
&lt;TR style="background-color: #d9e2f3;"&gt;
&lt;TD&gt;&lt;STRONG&gt;Date&lt;/STRONG&gt;&lt;/TD&gt;
&lt;TD&gt;&lt;STRONG&gt;Version&lt;/STRONG&gt;&lt;/TD&gt;
&lt;TD&gt;&lt;STRONG&gt;Author&lt;/STRONG&gt;&lt;/TD&gt;
&lt;TD&gt;&lt;STRONG&gt;Changes&lt;/STRONG&gt;&lt;/TD&gt;
&lt;/TR&gt;
&lt;/THEAD&gt;
&lt;TBODY&gt;
&lt;TR&gt;
&lt;TD&gt;2026-07-16&lt;/TD&gt;
&lt;TD&gt;1.0&lt;/TD&gt;
&lt;TD&gt;Jorge Luiz&lt;/TD&gt;
&lt;TD&gt;Initial version&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD&gt;2026-07-30&lt;/TD&gt;
&lt;TD&gt;2.0&lt;/TD&gt;
&lt;TD&gt;Jorge Luiz&lt;/TD&gt;
&lt;TD&gt;Cloud-first revalidation against the cloud Administration Guide: Web &amp;amp; Files Protection paths, cloud file actions (Prevent/Detect/Off + sub-options), Files Threat Emulation Mode, cloud sandbox knobs (size up to 100 MB, environments, block-on-failure), multi-browser support, &lt;CODE&gt;*&lt;/CODE&gt; in domain exclusions, Logs view; removed on-prem SmartEndpoint/SmartLog, Harmony Appliance IP/certificate and sk116381, and the unsourced "&amp;lt; 10 MB" cap&lt;/TD&gt;
&lt;/TR&gt;
&lt;/TBODY&gt;
&lt;/TABLE&gt;
&lt;HR /&gt;
&lt;P&gt;&lt;STRONG&gt;Supported Versions:&lt;/STRONG&gt; Harmony Endpoint cloud management (Infinity Portal / Web Management), Windows and macOS clients, supported browser extension &lt;STRONG&gt;Last Updated:&lt;/STRONG&gt; 2026-07-30&lt;/P&gt;
&lt;DIV id="gtx-trans" style="position: absolute; left: 670px; top: 3551.71px;"&gt;
&lt;DIV class="gtx-trans-icon"&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;/DIV&gt;</description>
      <pubDate>Tue, 18 Aug 2026 19:53:48 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Endpoint/EN-Threat-Emulation-amp-Extraction-Deep-Dive-The-Sandbox/m-p/281234#M11618</guid>
      <dc:creator>jorgeluiznim</dc:creator>
      <dc:date>2026-08-18T19:53:48Z</dc:date>
    </item>
  </channel>
</rss>

