ZIA: Investigate Sandbox
Keywords
sandbox, file blocked, quarantine, md5 hash, sandbox report, malware, atp, advanced threat protection, malware protection, file analysis, patient zero, patient 0, sandbox quota, file not scanning, quarantine stuck, sandbox verdict, behavioral analysis, unscannable file
Overview
Investigate ZIA Sandbox file analysis results and security policy enforcement issues. This skill combines API-driven sandbox inspection (reports, quota, behavioral analysis) with runbook-guided troubleshooting for Malware Protection, Advanced Threat Protection (ATP), and Sandbox policies.
Use this skill when: An administrator reports files being unexpectedly blocked or allowed, files stuck in quarantine, sandbox not analyzing files, missing Patient 0 alerts, or needs to verify a sandbox verdict for a specific file hash.
Workflow
Step 1: Gather Issue Details
Collect from the administrator:
Required:
- Symptom: file blocked, file allowed unexpectedly, file stuck in quarantine, sandbox not analyzing
- File MD5 hash (if available from Web Insights logs)
- URL or domain where the file was downloaded from
Helpful:
- Policy Action from Web Insights logs (e.g., "Sandbox Block", "Quarantined", "Allowed")
- Threat Super Category from Web Insights logs (e.g., "Sandbox", "Virus", "Malware Protection")
- Blocked Policy Type (e.g., "Sandbox", "Malware Protection", "Advanced Threat Protection")
- File type and size
- Sandbox subscription level (Basic vs Advanced)
Step 2: Determine the Security Control Involved
The Blocked Policy Type in Web Insights logs identifies which security control is responsible:
If the administrator knows the Blocked Policy Type, skip to the relevant section below.
Step 3: Sandbox Investigation (API-driven)
3A: Check Sandbox Report for a File
If an MD5 hash is available:

