---
sourceDocument: Australia Security Management
sourceDocumentLink: https://servicenow-prod.fluidtopics.net/r/pt-BR/security-management

 Release :

    - australia

ft:locale :

    - pt-BR

ft:publication_title :

    - Australia Security Management

ft:clusterId :

    - security

bundleId :

    - security

workflow :

    - Technology


---

# Submit observables to Sandbox

# Manually submit files or URLs to Sandbox {#ariaid-title1}

* Versão de lançamento: Australia
* 
* Atualizado 12 de mar. de 2026
* 
* ![](https://www.servicenow.com/docs/portal-asset/ico-clock) 1 min. de leitura

You can manually submit a file or URL to a sandbox when certain incident criteria, such as category is phishing, are met.

## Antes de Iniciar

Role required: sn_si.analyst

## Por Que e Quando Desempenhar Esta Tarefa

After reviewing the security incident and the file or URL, you can select the Submit to Sandbox option to perform a malware analysis.

## Procedimento

1. Navigate to AllSecurity IncidentIncidentsShow All Incidents and open a security incident to which you want to submit a file or URL observable type record.
2. Click the Show IoC related link.
3. On the Observables tab, select a record or multiple records for which you want to perform malware or threat analysis and click Submit to Sandbox.  
4. When the File Submission filter appears, select your preferred sandbox configuration in Submission configuration, and click Submit to Sandbox.  
5. **Opcional:** Select Additional runtime options if you want to provide further custom options.  
   {#submit-files-or-urls-to-sandbox__table_o55_bqy_ymb__entry__2}

   | Field | Description |
   |-|-|
   | Custom commandline | Regular application command line or a special operation. |
   | System date | System date in yyyy-MM-dd format. |
   | System time | System time in HH:mm format. |
   [ ]

   {#submit-files-or-urls-to-sandbox__table_o55_bqy_ymb}  
   After you initiate the submission, you can view the Work notes to see the status of your submission. For further information on the status of the submission or to analyze the results, view the Sandbox Submission Results.  
   Nota:  
   In CrowdStrike Falcon X Sandbox, quick scan isn't supported for URLs. If the worknotes has too much information, you can use the Filter option to drill down to the required worknotes that is relevant to you.

## O que Fazer Depois

When you submit the observables to the sandbox for malware analysis, [view the sandbox submission results](https://servicenow-prod.fluidtopics.net/n97DU_jtFl8KVqDNLW3cnA "Results for all Sandbox submissions are shown in the Sandbox Submission Results tab for every security incident.") to take the next steps on potential threats.

