Resource icon

Build a safer Windows Sandbox configuration for inspecting an unknown file

Windows Sandbox resets when closed, yet its default configuration allows networking and a custom mapped folder can expose host data. Microsoft's .wsb configuration gives you specific controls. For an unknown attachment or installer, the safer pattern is a disposable copy, network disabled if the task permits, and only a read-only host folder containing the one file. This does not make malware analysis risk-free, but it sharply narrows what the sample can touch.

Before you start​

Confirm Windows Sandbox is available on your supported Windows edition and enabled. Put the suspicious file in a dedicated folder with no personal documents. Keep Windows and security tools updated. Do not open a known malicious sample just to satisfy curiosity, and do not use a corporate sample outside incident-response policy. If a file requires Internet, decide whether testing it is worth the additional network exposure.

Do it step by step​

  1. Create a dedicated host folder containing only the file you intend to inspect. Copy the file there; leave originals and credentials elsewhere.
  2. Create a text file with a .wsb extension. Add a Configuration root, Networking set to Disable, and a MappedFolders entry whose HostFolder is the exact dedicated folder.
  3. Set ReadOnly to true for the mapped folder. Optionally disable vGPU and clipboard if the task does not need them; avoid sharing your entire Downloads or Documents folder.
  4. Save the configuration and open it with Windows Sandbox. Verify the mapped folder is visible, the copy is readable and a network request fails as expected.
  5. Inspect the file with a clear purpose. If the file asks for credentials or privileged access, stop; Sandbox is not a reason to enter real passwords or connect a real account.
  6. Close Sandbox when finished and confirm the session is discarded. Re-scan or delete the dedicated host copy according to your normal security process.

Check the result​

A fresh Sandbox opens with the intended limited mapping; host files outside the dedicated folder are not mapped, and networking is disabled when specified.

If something goes wrong​

If Sandbox will not start, validate .wsb XML and confirm the host folder exists. If the app truly requires Internet, test on a separate controlled machine rather than silently re-enabling networking. If mapped files change, ensure ReadOnly was set and the folder was not exposed elsewhere.

Know the limit​

Sandbox isolation is not a guarantee against every vulnerability or a replacement for endpoint protection. A mapped host folder can be compromised if writable; even read-only access can disclose its contents to the sandboxed process. Microsoft Sandbox configuration

Decision checkpoint​

The containment choice depends on the file's purpose. If you only need to inspect its text or metadata, do that without executing it. If running it is necessary for a legitimate investigation, document what you expect to observe and stop when behavior exceeds that plan. Never mount a folder containing browser profiles, password vaults or client data. If you must transfer an output file back to the host, scan and inspect it first; copied results are not automatically safe because they came from Sandbox.
Posted by
Jack
Views
3
First release
Last update

Ratings

0.00 star(s) 0 ratings

More resources from Jack