Skip to content
Identifying Vulnerabilities with Cloud Sandbox's Zero Day Virtual Machine Scan

Identifying Vulnerabilities with Cloud Sandbox's Zero Day Virtual Machine Scan

Zscaler • December 5, 2025

As a pioneer of cloud-based security, Zscaler operates a network of over 160 global data centers that have the necessary infrastructure to:

Zscaler’s Cloud Sandbox now provides customers an environment in which they can deploy new virtual machine (VM) types and apply the latest vendor-provided patches. Cloud Sandbox detonates sample binaries on a fully patched VM to derive a score based on a binary’s behavior: the higher the value, the greater the risk of exploitation. This blog looks at how Zscaler is able to achieve this and reduce patch deployment friction for security operations teams.

Operating the world’s largest security cloud platform means we can rapidly evaluate the behaviour and efficacy of the latest third-party vendor patches when applied. There are multiple nodes in Zscaler’s infrastructure that comprise the infrastructure required to execute data interception and inspection – here’s a look at what each edge component does:

Patch rollout is a very cumbersome process operationally for IT and security teams: they have to apply and verify that the patches were applied properly—and this process must be applied for multiple patches.

Before applying and rolling out patches, these teams would ideally have a rating that indicates how the patch impacts overall data flow in an organization, which could be any of the following:

All these outcomes could impact data flow, including if a new vulnerability is detected and if it could be blocked by security policies customers configure and add in their Zscaler tenant.

With such a rating, operations teams could make better decisions on which patches can be applied immediately without causing disruption versus those that pose more risk of interrupting workflows.

Zscaler’s Cloud Sandbox now provides customers an environment in which they can deploy new virtual machine types and apply the latest vendor-provided patches. Cloud Sandbox detonates these binaries on a fully patched VM to derive a score based on a binary’s behavior: the higher the value, the greater the risk of exploitation.

Comparing this score of a given binary on a fully patched VM (referred to as “Zero Day VM” going forward in this entry) helps customers understand the value of the patch.

For example, assuming the score of a binary in a regular unpatched VM is X and the same as Y on Zero Day VM we can determine the outcome would be the final one in this list of potential impacts:

Let’s look at an example of how this works: a customer submits a suspected zero-day exploit sample in two virtual machine environments: a "Regular VM" with limited patches and a "Zero Day VM" that was fully patched.

Despite the Zero Day VM being fully patched, the exploit was still successfully executed, confirming it was a true zero-day vulnerability. The resulting report below shows a threat score of 100 for the exploit. Further, the report also identifies behavioural characteristics that support this finding in addition to security bypass, networking and stealth tactics and techniques.

Zscaler's Cloud Sandbox effectively mitigated the threat. It not only accurately identified the novel exploit behavior but, more importantly, blocked the attack based on behavioral detection. This proves Cloud Sandbox’s ability to provide proactive protection against emerging threats by recognizing the underlying exploit technique (e.g., anomalous system calls, memory manipulation) rather than relying on a specific signature.

Esclusione di responsabilità: questo articolo del blog è stato creato da Zscaler esclusivamente a scopo informativo ed è fornito "così com'è", senza alcuna garanzia circa l'accuratezza, la completezza o l'affidabilità dei contenuti. Zscaler declina ogni responsabilità per eventuali errori o omissioni, così come per le eventuali azioni intraprese sulla base delle informazioni fornite. Eventuali link a siti web o risorse di terze parti sono offerti unicamente per praticità, e Zscaler non è responsabile del relativo contenuto, né delle pratiche adottate. Tutti i contenuti sono soggetti a modifiche senza preavviso. Accedendo a questo blog, l'utente accetta le presenti condizioni e riconosce di essere l'unico responsabile della verifica e dell'uso delle informazioni secondo quanto appropriato per rispondere alle proprie esigenze.

Inviando il modulo, si accetta la nostra Informativa sulla privacy .

Extracted Entities

Attack Types (1)

Platforms (1)