Y
yigido
Thread author
CCAV sandbox and CIS sandbox works in the same way about sandboxing procedure.thanks for explanations.
it sounds like CIS autosandbox works a little differently from CCAV autosandbox. In the latter, if I understand right, a file will only be trusted if it fulfills two conditions: signature is in TVL, and file is in "known files" list.
But CIS sandbox is stronger than CCAV sandbox
Here is the information from CCAV homepage
CCAV sandbox is a light weighted sandbox, it does not rely on service or filter drivers. It is implemented purely from user mode hooks. CCAV sandbox does not have COM/Service virtualization which CIS has. Besides, unlike CIS which has one global sandbox instance, different CCAV applications have their own sandbox instance while child process inherits sandbox instance from parent process