Capture ATP for SMA.
Four-engine cloud sandbox. Block until verdict.
Capture Advanced Threat Protection for SMA intercepts every file a remote user uploads through the SMA
6210, 7210, or 8200v and holds it in quarantine while SonicWall's cloud sandbox runs a verdict. Four
parallel analysis engines, including the patented Real-Time Deep Memory Inspection (RTDMI), examine each
file for ransomware, zero-day exploits, malicious Office documents, and threats designed to evade
traditional sandboxes. Files are released automatically when they clear, and blocked with an admin alert
when they do not.
Expert Pre-Sales AdviceCertified reps reply in 1 hour.
Config & Managed ServicesSkip the setup. We'll do it.
POs · Tax-Exempt · Net 30Welcomed for Corp, Edu, & Gov.
Same-Day ShippingOrder by 3pm EST, ships today.
How It Works
Capture ATP for SMA at a Glance
Intercept and Hold
When a remote user uploads a file through the SMA portal, the appliance intercepts it before it reaches
any internal file share, inbox, or application. The file sits in quarantine while Capture ATP works.
Nothing reaches your network until a verdict is returned. Administrators can configure which file types
are submitted, and can set policy to allow low-risk types through without analysis if the compliance
posture permits it.
Four Parallel Engines
Each submitted file runs through four analysis engines simultaneously. Full system emulation executes
the file in a complete virtualized OS environment. Hypervisor-level analysis monitors behavior from
outside the guest OS where malware cannot detect it. Virtualized sandboxing runs code in an isolated
environment and watches for malicious system calls. SonicWall RTDMI inspects file behavior directly in
CPU memory, catching threats that only arm themselves at execution time and would otherwise evade all
three behavioral engines.
RTDMI: What Sets It Apart
Real-Time Deep Memory Inspection is SonicWall's patented technique for catching evasion-first malware.
Many modern threats stay dormant in a sandbox environment and only activate in live memory during actual
execution. RTDMI forces the malware to reveal its payload in memory before it can execute its evasion
logic. Because the inspection happens in real time at the memory level, it catches threats that appear
clean under every behavioral test, with a low false-positive rate and no meaningful delay on file
verdicts for most file types.
Verdict, Reporting, and Shared Intelligence
Once a verdict is returned, clean files are released to the intended destination automatically. Blocked
files generate an admin alert with the file name, source, threat classification, and engine that
detected it. When a new threat is identified, SonicWall immediately publishes a signature to all Capture
ATP subscribers globally, so the threat is blocked on every subscribed appliance before it can reach a
second organization. A built-in threat analysis dashboard shows submission volume, verdicts by file
type, and trend data for the subscription period.
Need the SMA appliance too?
Capture ATP for SMA is an add-on subscription for the SMA 6210, 7210, and 8200v. If you are still
evaluating which appliance fits your user count and environment, the SMA 1000 Series overview page covers
all three with a side-by-side model comparison.
Capture ATP for SMA is a cloud-based advanced threat protection subscription for the
SonicWall SMA 6210, 7210, and 8200v. It intercepts files uploaded by remote users through the SMA
portal, quarantines them, and submits them to a four-engine cloud sandbox before releasing or blocking
them. The four engines are RTDMI, virtualized sandboxing, full system emulation, and hypervisor-level
analysis.
Capture ATP scans PE executables, DLLs, PDFs, Microsoft Office documents, archives,
JAR files, and APK files across Windows and Android platforms. Administrators can customize which file
types are submitted based on file type, size, sender, recipient, or protocol. Files can also be
submitted manually for analysis.
RTDMI, or Real-Time Deep Memory Inspection, is SonicWall's patented technique for
detecting threats that evade traditional sandbox analysis. Evasion-first malware is designed to detect
sandbox environments and stay dormant until it reaches a live system. RTDMI forces the malware to
reveal its payload in CPU memory at execution time, catching threats that appear clean under
behavioral analysis. For SMA deployments, this matters because remote users uploading files are an
entry point for exactly these kinds of targeted, evasion-aware threats.
Files are held in quarantine during analysis. For most common file types a verdict is
returned in seconds. Files that match known-clean signatures in SonicWall's threat intelligence
database can be cleared immediately without a full sandbox run. Administrators can configure policy to
allow specific low-risk file types to bypass the queue entirely, or to enforce block-until-verdict for
all submissions depending on the organization's risk tolerance.
Capture ATP for SMA is compatible with the SMA 6210, SMA 7210, and SMA 8200v running
SMA OS 12.4 or later. It is an optional subscription add-on. SMA appliances provide full remote access
functionality without it. It becomes relevant when your security policy or compliance framework
requires file-level inspection of content that remote users upload into the corporate network.
When Capture ATP identifies a new malicious file, SonicWall immediately generates a
signature and publishes it to all Capture ATP subscribers globally. This means every other
organization with a Capture ATP subscription is protected from that threat before it can reach a
second target. The threat is also logged in your appliance's threat analysis dashboard with source,
destination, and classification details.
Questions about adding Capture ATP to your SMA deployment?
Let us know which SMA appliance you are running, your current firmware version, and how many subscription
years you need. A SonicWall-certified engineer will confirm compatibility and come back with a quote
within one business hour.
Login and Registration Form
Existing User