Sandbox detonation reports
Identifies sandbox detonation reports patterns in security and access control contexts. Detects potential exposure of sensitive security information in international systems.
- Type
- regex
- Engine
- boost_regex
- Confidence
- medium
- Confidence justification
- structural regex with domain-specific anchors and constrained context replaces phrase-only marker. Added context gating and exclusion rules improve precision and reduce incidental matches.
- Detection quality
- Mixed
- Jurisdictions
- global
- Regulations
- GDPR
- Data categories
- credentials, security
- Scope
- wide
- Platform compatibility
- Purview: Compatible, GCP DLP: Compatible, Macie: Compatible, Zscaler: Compatible, Palo Alto: Degraded, Netskope: Unsupported
Pattern
(?is)\b(?:sandbox\s+detonation|sandbox\s+report|behavioral\s+analysis|malware\s+analysis|detonation\s+chamber|indicators\s+of\s+compromise|threat\s+intelligence|dynamic\s+analysis|static\s+analysis|payload\s+execution|command\s+and\s+control|network\s+traffic)\b
Corroborative evidence keywords
sandbox detonation reports, sandbox, detonation, reports, security, operations, threat, data
Proximity: 300 characters
Should match
sandbox detonation— Primary topic phrase matchsandbox report— Case-insensitive topic phrase matchbehavioral analysis— Alternative topic phrase matchmalware analysis— Additional topic phrase match
Should not match
unrelated generic text without domain phrases— No relevant topic phrases presentplaceholder value 12345— Random text should not match topic-specific regexdetonation ioc— Generic word pair from old broad template should not match
Known false positives
- Authentication-related terminology in software documentation, security training materials, or system architecture descriptions without actual credentials. Mitigation: Require proximity to credential-specific patterns (API keys, connection strings, tokens) rather than general security terminology.
- Code snippets and configuration examples containing credential-related keywords or placeholder values in developer documentation. Mitigation: Check for common placeholder patterns (example.com, localhost, 0000) and documentation file types to reduce false positives from technical writing.
References
- https://www.cyber.gov.au/resources-business-and-government/essential-cyber-security/ism
- https://www.legislation.gov.au/C2018A00029/latest/text
- https://www.oaic.gov.au/privacy/privacy-guidance-for-organisations-and-government-agencies/preventing-preparing-for-and-responding-to-data-breaches/data-breach-preparation-and-response
- https://handbook.apra.gov.au/standard/cps-234