Joe Sandbox

Updated 1 month ago by TruSTAR

This document explains how to set up the Joe Sandbox premium intelligence source in the TruSTAR platform.

Joe Sandbox executes files and URLs fully automated in a controlled environment and monitors the behavior of applications and the operating system for suspicious activities and compiles it in an extensive analysis report.

  • Source Type: Premium Intel
  • Update Type: Feed-based
  • Update Frequency: 15 minutes
  • Parser: Yes
  • Time to Install: 10 minutes

Observables Supported


  • Registered customer of Joe Security
  • Joe Sandbox Cloud API key
TruSTAR Admin rights are required to activate this Premium Intelligence feed.

Getting Started

  1. Log into the TruSTAR Web App.
  2. Click the Marketplace icon on the left side navigation bar.
  3. Choose Premium Intel.
  4. Click Subscribe in the Joe Sandbox icon.
  5. Enter your Joe Sandbox API key, then click Save Credentials & Request Subscription.

TruSTAR will validate the integration within 48 hours and send an email when the integration has been enabled.

TruSTAR Report Mapping

The information retrieved from this intelligence source is stored in the Joe Sandbox Enclave using this format.



Report Title

Sample field of target block of json response if available, else url field  

Example: WbPmrTtnkw

External ID

Encoded value of (webid) field of first json response

Example: encoded value of (752112)

Report Body

Full JSON response from Joe Sandbox

Time Begun

Combined start_date and start_time field of second json response

Example: 20/12/2019 19:48:25


Score and malicious field of signature detections field of json response

Example: [“confidence:64”, “Maliciousness:true”]


Example: XXXX

Client Type


Client Meta Tag


Known Issues

None reported.

Please contact if you have issues with this integration.

How Did We Do?