Skip to main content
Sticky

How to submit files for Sandbox scanning via API

  • March 19, 2024
  • 0 replies
  • 112 views

Forum|alt.badge.img+6

AD_4nXeqT6Ei1OMGjCZS1WffsFyCAUJ0eGvONAsHANy-c8d0CESxNX1R1-_pYLG-JDMzD-JZoQeejtpI9Iz4gLbII3fSG85sCiUmdti7htylRZ0S0r4c6zJ1BO5RvgUWsxK58G6shOQV2FXwB2jrN0lecgdJfbY?key=cSS7ULJYO9kgIH0dkCUyXg

Netskope Global Technical Success (GTS)

KB - Submit files for Sandbox scanning via API

 

Netskope Cloud Version - 128

 

Objective

To demonstrate the process for submitting files for Sandbox scanning via API

 

Prerequisite

Netskope Advanced Threat protection license is required

Backend flags : Sandbox File Submission API needs to be enabled. Contact your Account CSM / TAM / TSM for the enablement.

 

Context

Netskope allows submitting files for Sandbox scanning via API as well. This KB will give details about the process to follow for submitting files for Sandbox scanning via API

 

Lab Recreate:

This process requires two API endpoint as shown below :

 

Go to Settings – Tools – Rest API V2 and create a new token with the below permissions :

 

AD_4nXdjIvdkQ36DqBAvhKprXEOUIxHaW8u7SPYByKx0zHFD798yVWRC9SHHUq3Hz6yZD1k35HSD-iYs_q8UKxkNDXEayoVCqMO7_CBBWVw0ei95OmSsl4KQ5JI2vYabZMzeIVUrz7l1a6r95OLMerO1IQpT9xYt?key=cSS7ULJYO9kgIH0dkCUyXg

 

Click on “Save” and then copy the token 

 

A screenshot of a computerDescription automatically generated

 

Now click on API Documentation and go to the Swagger UI

 

A screenshot of a applicationDescription automatically generated

 

On the Swagger UI, click on Authorise, enter the token created above.

 

A screenshot of a computerDescription automatically generated

 

Now look for the ATP API requests and click on “Try it Out”

 

AD_4nXfbCldAho5TeL_H-XvXXhuVXxSA9Vk6-bdsCUlcGeZhhjl66XIRoZqzkW0y2VeXNYIRiBxKoBIgcdKoV3agGWJ_T7LtDH6mVvPvI_AZmdhsb9Sm2mRTsodYYy-FQC_VXhCHxHWq7A?key=cSS7ULJYO9kgIH0dkCUyXg

 

Now, add the scan type as “sandbox”, choose the file that you want to sent to the sandbox scan and choose execute

 

AD_4nXfIDd5RfTAZz2ZuUI7sMsl3_U9-71bnMQIRLjZ-moV4TJkZW0dnnKHJlwOwmc3xMGWRVhFexo3vM9g6NwVkSNOzOAIk3lqPsFuRhSnjf2neEfD7s9se1v297PZMR89kUy2cDLw08JnqSSGOGT9a_84-IcIK?key=cSS7ULJYO9kgIH0dkCUyXg

 

Once the scan is done, you get the result as below with the Job ID, copy that Job ID :

 

A screenshot of a computer programDescription automatically generated

 

Now enter this Job ID in the below API Query and run execute to get a detailed Report of the Sandbox file submitted earlier


 

A screenshot of a computerDescription automatically generated

 

Terms and Conditions

  • API to submit a password protected .zip file with password “infected” for scan by Netskope sandbox
  • Supported member file types in the zip: .exe, .pdf, .doc, .xls, .ppt and .rtf
  • Total files in the Zip : 1
  • API accepts files up to 16 MB
  • up to 1,000 files can be submitted per day ('/filescan' endpoint)
  • up to 10,000 queries can be submitted per day ('/reports' endpoint)

Notes

  • This article is authored by Netskope Global Technical Success (GTS).
  • For any further inquiries related to this article, please contact Netskope GTS by submitting a support case with 'Case Type – How To Questions'.
This topic has been closed for replies.