Capture ATP for SMA.
Four-engine cloud sandbox. Block until verdict.
Capture Advanced Threat Protection holds every file your remote users upload in quarantine while
SonicWall's cloud sandbox checks it for ransomware, zero-day exploits, and evasive malware. Clean files are
released automatically, and anything malicious is blocked before it reaches your network, with an alert to
your admins.
Expert Pre-Sales AdviceCertified reps reply in 1 hour.
Config & Managed ServicesSkip the setup. We'll do it.
POs · Tax-Exempt · Net 30Welcomed for Corp, Edu, & Gov.
Same-Day ShippingOrder by 3pm EST, ships today.
How It Works
Capture ATP for SMA at a Glance
Intercept and Hold
When a remote user uploads a file through the SMA portal, it is held in quarantine before it reaches
any
file share, inbox, or application. Nothing enters your network until Capture ATP returns a verdict, and
admins can set policy for which file types are submitted.
Four Parallel Engines
Every file runs through four engines at once. Full system emulation, hypervisor-level analysis, and
virtualized sandboxing watch its behavior from different angles, while SonicWall RTDMI inspects it
directly in CPU memory. Together they catch threats that any single engine would miss.
RTDMI: What Sets It Apart
Real-Time Deep Memory Inspection is SonicWall's patented method for catching evasion-first malware that
stays dormant in traditional sandboxes. RTDMI forces the payload to reveal itself in CPU memory at
execution time, catching threats that pass every behavioral test, with a low false-positive rate.
Verdict, Reporting, and Shared Intelligence
Clean files are released automatically, while blocked files trigger an admin alert with the source and
threat classification. New threats are shared immediately with Capture ATP subscribers worldwide, and a
built-in dashboard tracks submissions, verdicts, and trends for your subscription.
Need the SMA appliance too?
Still deciding between the SMA 6210 and 7210? Our Secure Mobile Access page puts them side by side so you
can match the right appliance to your user count and environment.
Capture ATP for SMA is a cloud-based advanced threat protection subscription for the
SonicWall SMA 6210, 7210, and 8200v. It intercepts files uploaded by remote users through the SMA
portal, quarantines them, and submits them to a four-engine cloud sandbox before releasing or blocking
them. The four engines are RTDMI, virtualized sandboxing, full system emulation, and hypervisor-level
analysis.
Capture ATP scans PE executables, DLLs, PDFs, Microsoft Office documents, archives,
JAR files, and APK files across Windows and Android platforms. Administrators can customize which file
types are submitted based on file type, size, sender, recipient, or protocol. Files can also be
submitted manually for analysis.
RTDMI, or Real-Time Deep Memory Inspection, is SonicWall's patented technique for
detecting threats that evade traditional sandbox analysis. Evasion-first malware is designed to detect
sandbox environments and stay dormant until it reaches a live system. RTDMI forces the malware to
reveal its payload in CPU memory at execution time, catching threats that appear clean under
behavioral analysis. For SMA deployments, this matters because remote users uploading files are an
entry point for exactly these kinds of targeted, evasion-aware threats.
Files are held in quarantine during analysis. For most common file types a verdict is
returned in seconds. Files that match known-clean signatures in SonicWall's threat intelligence
database can be cleared immediately without a full sandbox run. Administrators can configure policy to
allow specific low-risk file types to bypass the queue entirely, or to enforce block-until-verdict for
all submissions depending on the organization's risk tolerance.
Capture ATP for SMA is compatible with the SMA 6210, SMA 7210, and SMA 8200v running
SMA OS 12.4 or later. It is an optional subscription add-on. SMA appliances provide full remote access
functionality without it. It becomes relevant when your security policy or compliance framework
requires file-level inspection of content that remote users upload into the corporate network.
When Capture ATP identifies a new malicious file, SonicWall immediately generates a
signature and publishes it to all Capture ATP subscribers globally. This means every other
organization with a Capture ATP subscription is protected from that threat before it can reach a
second target. The threat is also logged in your appliance's threat analysis dashboard with source,
destination, and classification details.
Questions about adding Capture ATP to your SMA deployment?
Let us know which SMA appliance you are running, your current firmware version, and how many subscription
years you need. A SonicWall-certified engineer will confirm compatibility and come back with a quote
within one business hour.
Login and Registration Form
Existing User