Skip to main content

Check Point Threat Emulation (SandBlast)

Download With Dependencies

Upload files using polling, the service supports Microsoft Office files, as well as PDF, SWF, archives and executables. Active content will be cleaned from any documents that you upload (Microsoft Office and PDF files only). Query on existing IOCs, file status, analysis, reports. Download files from the database. Supports both appliance and cloud. Supported Threat Emulation versions are any R80x.

Check Point Threat Emulation (SandBlast) Pack

What does this pack do?

  • Uses Threat Emulation to perform remote analysis on a sandbox.
  • Uploads files to a virtual sandbox.
  • Opens files and monitors them in multiple OS versions and Microsoft Office versions.
  • Saves malicious files in the ThreatCloud.
  • Provides a safe file without active content while the original file is inspected by Threat Emulation. If it is safe it can be downloaded.




Cortex XSOARCortex XSIAM


CertificationRead more
Supported ByCortex
CreatedAugust 16, 2022
Last ReleaseSeptember 12, 2023

Content packs are licensed by the Publisher identified above and subject to the Publisher’s own licensing terms. Palo Alto Networks is not liable for and does not warrant or support any content pack produced by a third-party Publisher, whether or not such packs are designated as “Palo Alto Networks-certified” or otherwise. For more information, see the Marketplace documentation.