Netskope Advance Threat Protection does have a sandbox/research feature to investigate files that are downloaded with a sandbox examination, amongst other things. Having an alert later on that a file is malicious gives a reason for follow-up on that person/computer.
They also have a policy suggestion, where novel files are not downloadable until after they pass a sandbox exception. The devil is in the details "The Netskope advanced threat engines can take up to 10 minutes to analyze the file." Also, in practice, if you the download just fails for 10 minutes of clicking on it, no pop-up warning you that it is in review.
So I am dying to know - has anyone actually done this policy?
I am also fascinated by the policy example, where the policy is applied to downloads of Adult Content and Adult Content - Porn. The net effect would be "As a company it is OK to go to a porn site and download from it, but you have to wait 10 minutes while we check out the download"
Wouldn't it be better to put the file aside and send the person an email with a link from Netskope? and download it from Netskope?