Microsoft Defender feature that detonates email attachments in sandbox environments to detect malware.
Safe Attachments is a Microsoft Defender for Office 365 feature that opens email attachments in isolated sandbox environments (detonation) to detect malicious behaviour before delivering to users. Unlike signature-based scanning (which only catches known malware), Safe Attachments observes actual behaviour—whether files try to download malware, connect to command servers, or execute malicious code. Suspicious attachments can be blocked or delivered with warnings.
Why It Matters
The DSC Perspective:
Traditional antivirus misses new malware variants. Safe Attachments catches zero-day threats through behavioural analysis. Essential for protection against targeted attacks using custom malware.
