List available VPN exit points and regional tags for geographic routing in sandbox analysis.
What this endpoint does
Lists all available VPN exit points for geographic routing during sandbox analysis. Use these geolocation identifiers when creating profiles with network: "vpn" via Sandbox: Create Profile, or when specifying geolocation inline during Sandbox: Submit Sample. Geographic routing lets you analyze region-targeted threats — malware that behaves differently based on the victim's geographic location, or phishing pages that only serve content to specific countries.
Response data
Returns available VPN exit points grouped by sandbox backend. Each geolocation has a tunnel name (e.g., tun-ca-toronto, de-germa-so-tun) to use as the geolocation parameter value, and tags for filtering by region (e.g., us, europe, asia). Multiple backends may offer overlapping geolocations — the sandbox selects the appropriate backend automatically. Use the tags to search for geolocations by region when the exact tunnel name isn't known.
