Windows Sandbox resets when closed, yet its default configuration allows networking and a custom mapped folder can expose host data. Microsoft's .wsb configuration gives you specific controls. For an unknown attachment or installer, the safer pattern is a disposable copy, network disabled if the task permits, and only a read-only host folder containing the one file. This does not make malware analysis risk-free, but it sharply narrows what the sample can touch.
Before you start
Confirm Windows Sandbox is available on your supported Windows edition and enabled. Put the suspicious file in a dedicated folder with no personal documents. Keep Windows and security tools updated. Do not open a known malicious sample just to satisfy curiosity, and do not use a corporate sample outside incident-response policy. If a file requires Internet, decide whether testing it is worth the additional network exposure.Do it step by step
- Create a dedicated host folder containing only the file you intend to inspect. Copy the file there; leave originals and credentials elsewhere.
- Create a text file with a .wsb extension. Add a Configuration root, Networking set to Disable, and a MappedFolders entry whose HostFolder is the exact dedicated folder.
- Set ReadOnly to true for the mapped folder. Optionally disable vGPU and clipboard if the task does not need them; avoid sharing your entire Downloads or Documents folder.
- Save the configuration and open it with Windows Sandbox. Verify the mapped folder is visible, the copy is readable and a network request fails as expected.
- Inspect the file with a clear purpose. If the file asks for credentials or privileged access, stop; Sandbox is not a reason to enter real passwords or connect a real account.
- Close Sandbox when finished and confirm the session is discarded. Re-scan or delete the dedicated host copy according to your normal security process.