On 18th March 2020, @Jonathango , @einats , and @ranl gave a TechTalk about how you can prevent malicious web downloads using SandBlast.
Content available to CheckMates members:
Q&A from the session follows
How is Sandboxing Licensed?
In our product, we refer to Sandboxing technology as Threat Emulation. It is part of the NGTX licensing bundle sold with or as an add-on to existing appliances.
Where does the emulation take place?
Emulation can either take place in the cloud or on specific on-premise appliances that must be purchased separately. You can explicitly configure where files are sent?
What Data is Sent to the Cloud during Emulation?
See our Cloud Services Security Statement.
Can you easily generate/run reports to indicate total file downloads, files scanned, sanitized & possibly identified as malicious, etc?
Yes, as part of SmartEvent.
Is this a replacement for standard Anti-Virus on the Client?
No, it is one of many technologies we provide as part of our Check Point Infinity approach, which provides multiple types of protection at multiple points in the environment.
In this session, we specifically covered what we can do on the gateway. We have a similar product that can be deployed on the client called SandBlast Agent which would be a replacement for a traditional AV client.